CVE Vulnerabilities

CVE-2005-4534

Published: Dec 28, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

Affected Software

NameVendorStart VersionEnd Version
BugzillaMozilla2.9 (including)2.9 (including)
BugzillaMozilla2.10 (including)2.10 (including)
BugzillaMozilla2.12 (including)2.12 (including)
BugzillaMozilla2.14 (including)2.14 (including)
BugzillaMozilla2.14.1 (including)2.14.1 (including)
BugzillaMozilla2.14.2 (including)2.14.2 (including)
BugzillaMozilla2.14.3 (including)2.14.3 (including)
BugzillaMozilla2.14.4 (including)2.14.4 (including)
BugzillaMozilla2.14.5 (including)2.14.5 (including)
BugzillaMozilla2.16 (including)2.16 (including)
BugzillaMozilla2.16.1 (including)2.16.1 (including)
BugzillaMozilla2.16.2 (including)2.16.2 (including)
BugzillaMozilla2.16.3 (including)2.16.3 (including)
BugzillaMozilla2.16.4 (including)2.16.4 (including)
BugzillaMozilla2.16.5 (including)2.16.5 (including)
BugzillaMozilla2.16.6 (including)2.16.6 (including)
BugzillaMozilla2.16.7 (including)2.16.7 (including)
BugzillaMozilla2.16.8 (including)2.16.8 (including)
BugzillaMozilla2.16.9 (including)2.16.9 (including)
BugzillaMozilla2.16.10 (including)2.16.10 (including)
BugzillaUbuntuupstream*

References