CVE-2005-2693

8 documents8 sources
Severity
4.6MEDIUM
EPSS
0.1%
top 77.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 26
Latest updateMay 3

Description

cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages2 packages

Debiancvs< 1:1.11.5-4+3
NVDcvs/cvs1.12.12

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rfjx-5fv4-2g47: cvsbug in CVS 12022-05-03
OSV
CVE-2005-2693: cvsbug in CVS 12005-08-26
CVEList
CVE-2005-2693: cvsbug in CVS 12005-08-25

📋Vendor Advisories

2
Red Hat
security flaw2005-08-19
Debian
CVE-2005-2693: cvs - cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allo...2005

💬Community

1
Bugzilla
CVE-2005-2693 security flaw2018-08-16