CPANSA-Mail-Audit-2005-4536: Mail-Audit vulnerability
Publisher | giterlizzi | Document category | csaf_security_advisory |
---|---|---|---|
Initial release date | 2005-12-31T00:00:00 | Engine | CSAF Perl Toolkit 0.25 |
Current release date | 2005-12-31T00:00:00 | Build Date | |
Current version | 1 | Status | final |
CVSS v3.1 Base Score | Severity | ||
Original language | Language | en | |
Also referred to |
Vulnerability Description
Mail::Audit module in libmail-audit-perl 2.1-5, when logging is enabled without a default log file specified, uses predictable log filenames, which allows local users to overwrite arbitrary files via a symlink attack on the [PID]-audit.log temporary file.
Vulnerabilities
CVE-2005-4536
Vulnerability DescriptionMail::Audit module in libmail-audit-perl 2.1-5, when logging is enabled without a default log file specified, uses predictable log filenames, which allows local users to overwrite arbitrary files via a symlink attack on the [PID]-audit.log temporary file.
Product status
Known affected
Product | Score | ||||||||
---|---|---|---|---|---|---|---|---|---|
Mail-Audit greater than 0 |
|
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Mail-Audit-2005-4536 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2005/cpansa-mail-audit-2005-4536.json - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=344029 external
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=344029 - http://www.debian.org/security/2006/dsa-960 external
http://www.debian.org/security/2006/dsa-960 - http://secunia.com/advisories/18652 external
http://secunia.com/advisories/18652 - http://secunia.com/advisories/18656 external
http://secunia.com/advisories/18656 - http://www.securityfocus.com/bid/16434 external
http://www.securityfocus.com/bid/16434 - http://www.vupen.com/english/advisories/2006/0378 external
http://www.vupen.com/english/advisories/2006/0378 - https://exchange.xforce.ibmcloud.com/vulnerabilities/24380 external
https://exchange.xforce.ibmcloud.com/vulnerabilities/24380 - CVE-2005-4536 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2005-4536
Revision history
Version | Date of the revision | Summary of the revision |
---|---|---|
1 | Sat Dec 31 00:00:00 2005 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/