CVE-2005-3137

Publication date 5 October 2005

Last updated 24 July 2024


Ubuntu priority

The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
cfengine 7.04 feisty Not in release
6.10 edgy
Fixed 1.6.5-2ubuntu1
6.06 LTS dapper
Fixed 1.6.5-2ubuntu1

References

Related Ubuntu Security Notices (USN)

    • USN-198-1
    • cfengine vulnerabilities
    • 10 October 2005

Other references