CVE-2005-0990
published 2005-05-02CVE-2005-0990: unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.
PriorityP47low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.36%
28.3th percentile
unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sharutils | < sharutils 1:4.2.1-13 (bookworm) | sharutils 1:4.2.1-13 (bookworm) |
| gnu | sharutils | — | — |
| gnu | sharutils | >= 0 < 1:4.2.1-13 | 1:4.2.1-13 |
| gnu | sharutils | >= 0 < 1:4.2.1-13 | 1:4.2.1-13 |
| gnu | sharutils | >= 0 < 1:4.2.1-13 | 1:4.2.1-13 |
| gnu | sharutils | >= 0 < 1:4.2.1-13 | 1:4.2.1-13 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2005-03-31·CVSS 2.1
CVE-2005-0990 [LOW] security flaw
security flaw
unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.
Debian
CVE-2005-0990: sharutils - unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary f...
vendor_debian·2005·CVSS 2.1
CVE-2005-0990 [LOW] CVE-2005-0990: sharutils - unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary f...
unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.
Scope: local
bookworm: resolved (fixed in 1:4.2.1-13)
bullseye: resolved (fixed in 1:4.2.1-13)
forky: resolved (fixed in 1:4.2.1-13)
sid: resolved (fixed in 1:4.2.1-13)
trixie: resolved (fixed in 1:4.2.1-13)
GHSA
GHSA-358m-xcjh-x4vp: unshar (unshar
ghsa_unreviewed·2022-05-01
CVE-2005-0990 [LOW] GHSA-358m-xcjh-x4vp: unshar (unshar
unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.
OSV
CVE-2005-0990: unshar (unshar
osv·2005-05-02·CVSS 2.1
CVE-2005-0990 [LOW] CVE-2005-0990: unshar (unshar
unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=302412http://www.redhat.com/support/errata/RHSA-2005-377.htmlhttp://www.securityfocus.com/bid/12981https://bugzilla.ubuntu.com/show_bug.cgi?id=8459https://exchange.xforce.ibmcloud.com/vulnerabilities/19957https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9613https://usn.ubuntu.com/104-1/http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=302412http://www.redhat.com/support/errata/RHSA-2005-377.htmlhttp://www.securityfocus.com/bid/12981https://bugzilla.ubuntu.com/show_bug.cgi?id=8459https://exchange.xforce.ibmcloud.com/vulnerabilities/19957https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9613https://usn.ubuntu.com/104-1/
2005-05-02
Published