The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freebsd | Freebsd | 4.10 (including) | 4.10 (including) |
Freebsd | Freebsd | 4.10-release (including) | 4.10-release (including) |
Freebsd | Freebsd | 4.10-release_p8 (including) | 4.10-release_p8 (including) |
Freebsd | Freebsd | 4.10-releng (including) | 4.10-releng (including) |
Freebsd | Freebsd | 4.11-release_p3 (including) | 4.11-release_p3 (including) |
Freebsd | Freebsd | 4.11-releng (including) | 4.11-releng (including) |
Freebsd | Freebsd | 4.11-stable (including) | 4.11-stable (including) |
Freebsd | Freebsd | 5.0 (including) | 5.0 (including) |
Freebsd | Freebsd | 5.0-alpha (including) | 5.0-alpha (including) |
Freebsd | Freebsd | 5.0-release_p14 (including) | 5.0-release_p14 (including) |
Freebsd | Freebsd | 5.0-releng (including) | 5.0-releng (including) |
Freebsd | Freebsd | 5.1 (including) | 5.1 (including) |
Freebsd | Freebsd | 5.1-alpha (including) | 5.1-alpha (including) |
Freebsd | Freebsd | 5.1-release (including) | 5.1-release (including) |
Freebsd | Freebsd | 5.1-release_p5 (including) | 5.1-release_p5 (including) |
Freebsd | Freebsd | 5.1-releng (including) | 5.1-releng (including) |
Freebsd | Freebsd | 5.2 (including) | 5.2 (including) |
Freebsd | Freebsd | 5.2.1-release (including) | 5.2.1-release (including) |
Freebsd | Freebsd | 5.2.1-releng (including) | 5.2.1-releng (including) |
Freebsd | Freebsd | 5.3 (including) | 5.3 (including) |
Freebsd | Freebsd | 5.3-release (including) | 5.3-release (including) |
Freebsd | Freebsd | 5.3-releng (including) | 5.3-releng (including) |
Freebsd | Freebsd | 5.3-stable (including) | 5.3-stable (including) |
Freebsd | Freebsd | 5.4-pre-release (including) | 5.4-pre-release (including) |
Freebsd | Freebsd | 5.4-release (including) | 5.4-release (including) |
Freebsd | Freebsd | 5.4-releng (including) | 5.4-releng (including) |
Freebsd | Freebsd | 6.0-release (including) | 6.0-release (including) |
Freebsd | Freebsd | 6.0-stable (including) | 6.0-stable (including) |
Ee | Ubuntu | dapper | * |
Ee | Ubuntu | devel | * |
Ee | Ubuntu | edgy | * |
Ee | Ubuntu | feisty | * |
Ee | Ubuntu | gutsy | * |