CVE-2005-2693
published 2005-08-26CVE-2005-2693: cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a…
PriorityP417medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.44%
37.2th percentile
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cvs | cvs | — | — |
| cvs | cvs | >= 0 < 1:1.11.5-4 | 1:1.11.5-4 |
| cvs | cvs | >= 0 < 1:1.11.5-4 | 1:1.11.5-4 |
| cvs | cvs | >= 0 < 1:1.11.5-4 | 1:1.11.5-4 |
| cvs | cvs | >= 0 < 1:1.11.5-4 | 1:1.11.5-4 |
| debian | cvs | < cvs 1:1.11.5-4 (bookworm) | cvs 1:1.11.5-4 (bookworm) |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6LOW
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2005-08-19·CVSS 4.6
CVE-2005-2693 [MEDIUM] security flaw
security flaw
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2005-2693: cvs - cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allo...
vendor_debian·2005·CVSS 4.6
CVE-2005-2693 [MEDIUM] CVE-2005-2693: cvs - cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allo...
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
Scope: local
bookworm: resolved (fixed in 1:1.11.5-4)
bullseye: resolved (fixed in 1:1.11.5-4)
forky: resolved (fixed in 1:1.11.5-4)
sid: resolved (fixed in 1:1.11.5-4)
trixie: resolved (fixed in 1:1.11.5-4)
GHSA
GHSA-rfjx-5fv4-2g47: cvsbug in CVS 1
ghsa_unreviewed·2022-05-03
CVE-2005-2693 [MEDIUM] GHSA-rfjx-5fv4-2g47: cvsbug in CVS 1
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
OSV
CVE-2005-2693: cvsbug in CVS 1
osv·2005-08-26·CVSS 4.6
CVE-2005-2693 [MEDIUM] CVE-2005-2693: cvsbug in CVS 1
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
No detection rules found.
No public exploits indexed.
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:20.cvsbug.aschttp://secunia.com/advisories/16765http://securitytracker.com/id?1014857http://www.debian.org/security/2005/dsa-802http://www.debian.org/security/2005/dsa-806http://www.redhat.com/support/errata/RHSA-2005-756.htmlhttp://www.vupen.com/english/advisories/2005/1667https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166366https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10835ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:20.cvsbug.aschttp://secunia.com/advisories/16765http://securitytracker.com/id?1014857http://www.debian.org/security/2005/dsa-802http://www.debian.org/security/2005/dsa-806http://www.redhat.com/support/errata/RHSA-2005-756.htmlhttp://www.vupen.com/english/advisories/2005/1667https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166366https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10835
2005-08-26
Published