CVE-2005-2991

ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ncompress:ncompress:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:00

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=112689772732098&w=2 - () http://marc.info/?l=bugtraq&m=112689772732098&w=2 -
References () http://marc.info/?l=full-disclosure&m=112688098630314&w=2 - () http://marc.info/?l=full-disclosure&m=112688098630314&w=2 -
References () http://securityreason.com/securityalert/12 - () http://securityreason.com/securityalert/12 -
References () http://www.zataz.net/adviso/ncompress-09052005.txt - Vendor Advisory () http://www.zataz.net/adviso/ncompress-09052005.txt - Vendor Advisory

Information

Published : 2005-09-20 20:03

Updated : 2025-04-03 01:03


NVD link : CVE-2005-2991

Mitre link : CVE-2005-2991

CVE.ORG link : CVE-2005-2991


JSON object : View

Products Affected

ncompress

  • ncompress