CVE-2006-5072Mono vulnerability

6 documents6 sources
Severity
6.2MEDIUMNVD
EPSS
0.1%
top 81.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 10
Latest updateMay 1

Description

The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack.

CVSS vector

AV:L/AC:H/C:C/I:C/A:CExploitability: 1.9 | Impact: 10.0

Affected Packages3 packages

debiandebian/mono< mono 1.1.17.1-5 (bookworm)
Debianmono/mono< 1.1.17.1-5+3
NVDmono/mono1.0, 2.0+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-388g-rj94-7qvv: The System2022-05-01
OSV
CVE-2006-5072: The System2006-10-10
CVEList
CVE-2006-5072: The System2006-10-05

📋Vendor Advisories

2
Ubuntu
Mono vulnerability2006-10-05
Debian
CVE-2006-5072: mono - The System.CodeDom.Compiler classes in Novell Mono create temporary files with i...2006