CVE Vulnerabilities

CVE-2005-2918

Published: Sep 15, 2005 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The open_cmd_tube function in mount.c for gtkdiskfree 1.9.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the gtkdiskfree temporary file.

Affected Software

Name Vendor Start Version End Version
Gtkdiskfree Gtkdiskfree * 1.9.3 (including)
Gtkdiskfree Ubuntu dapper *
Gtkdiskfree Ubuntu devel *
Gtkdiskfree Ubuntu edgy *
Gtkdiskfree Ubuntu feisty *

References