CVE-2006-6939

9 documents7 sources
Severity
4.6MEDIUM
EPSS
0.1%
top 72.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 17
Latest updateMay 1

Description

GNU ed before 0.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files, possibly in the open_sbuf function.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages2 packages

Debianed< 0.2-19+3
NVDgnu/ed0.2

🔴Vulnerability Details

3
GHSA
GHSA-q7jc-952h-fjg4: GNU ed before 02022-05-01
OSV
CVE-2006-6939: GNU ed before 02007-01-17
CVEList
CVE-2006-6939: GNU ed before 02007-01-17

📋Vendor Advisories

2
Red Hat
CVE-2006-6939 Insecure use of temporary file in ed2007-11-11
Debian
CVE-2006-6939: ed - GNU ed before 0.3 allows local users to overwrite arbitrary files via a symlink ...2006

💬Community

3
Bugzilla
CVE-2006-6939 Insecure use of temporary file in ed2007-01-17
Bugzilla
CVE-2006-6939 Insecure use of temporary file in ed2007-01-17
Bugzilla
CVE-2006-6939 Insecure use of temporary file in ed2007-01-17
CVE-2006-6939 (MEDIUM CVSS 4.6) | GNU ed before 0.3 allows local user | cvebase.io