CVE Vulnerabilities

CVE-2006-0055

Published: Jan 11, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 5.4 5.4
Freebsd Freebsd 5.3 5.3
Freebsd Freebsd 5.1 5.1
Freebsd Freebsd 5.3 5.3
Freebsd Freebsd 5.1 5.1
Freebsd Freebsd 5.2.1 5.2.1
Freebsd Freebsd 5.0 5.0
Freebsd Freebsd 5.1 5.1
Freebsd Freebsd 5.0 5.0
Freebsd Freebsd 5.1 5.1
Freebsd Freebsd 4.10 4.10
Freebsd Freebsd 4.11 4.11
Freebsd Freebsd 4.10 4.10
Freebsd Freebsd 5.1 5.1
Freebsd Freebsd 5.2 5.2
Freebsd Freebsd 4.11 4.11
Freebsd Freebsd 4.10 4.10
Freebsd Freebsd 5.4 5.4
Freebsd Freebsd 6.0 6.0
Freebsd Freebsd 4.10 4.10
Freebsd Freebsd 5.4 5.4
Freebsd Freebsd 5.0 5.0
Freebsd Freebsd 5.2.1 5.2.1
Freebsd Freebsd 5.0 5.0
Freebsd Freebsd 6.0 6.0
Freebsd Freebsd 5.3 5.3
Freebsd Freebsd 5.3 5.3
Freebsd Freebsd 4.11 4.11

References