CVE Vulnerabilities

CVE-2004-0996

Published: Jan 10, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.

Affected Software

Name Vendor Start Version End Version
Cscope Cscope 13.0 13.0
Cscope Cscope 15.1 15.1
Cscope Cscope 15.3 15.3
Cscope Cscope 15.4 15.4
Cscope Cscope 15.5 15.5
Cscope Ubuntu dapper *
Cscope Ubuntu devel *
Cscope Ubuntu edgy *
Cscope Ubuntu feisty *

References