4.6

CVE-2005-1064

The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access to arbitrary files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.276
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=full-disclosure&m=111317179531000&w=2
http://secunia.com/advisories/14878
Patch
Vendor Advisory
http://securitytracker.com/id?1013674
Patch
Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200504-12.xml
Patch
Vendor Advisory
http://www.osvdb.org/15420
http://www.rsnapshot.org/security/2005/001.html
Patch
Vendor Advisory