2.1

CVE-2005-2960

cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by vicf.in, a different vulnerability than CVE-2005-3137.

Data is provided by the National Vulnerability Database (NVD)
GnuCfengine Version1.5
GnuCfengine Version1.5.3-4
GnuCfengine Version1.6 Updatea10
GnuCfengine Version1.6 Updatea11
GnuCfengine Version1.6.5
GnuCfengine Version2.0.0
GnuCfengine Version2.0.1
GnuCfengine Version2.0.2
GnuCfengine Version2.0.3
GnuCfengine Version2.0.4
GnuCfengine Version2.0.5
GnuCfengine Version2.0.5 Updateb1
GnuCfengine Version2.0.5 Updatepre
GnuCfengine Version2.0.5 Updatepre2
GnuCfengine Version2.0.6
GnuCfengine Version2.0.7
GnuCfengine Version2.0.7 Updatep1
GnuCfengine Version2.0.7 Updatep2
GnuCfengine Version2.0.7 Updatep3
GnuCfengine Version2.0.8
GnuCfengine Version2.0.8 Updatep1
GnuCfengine Version2.1.0 Updatea6
GnuCfengine Version2.1.0 Updatea8
GnuCfengine Version2.1.0 Updatea9
GnuCfengine Version2.1.7 Updatep1
GnuCfengine Version2.1.8
GnuCfengine Version2.1.9
GnuCfengine Version2.1.16
DebianDebian Linux Version3.1
DebianDebian Linux Version3.1 Editionalpha
DebianDebian Linux Version3.1 Editionamd64
DebianDebian Linux Version3.1 Editionarm
DebianDebian Linux Version3.1 Editionhppa
DebianDebian Linux Version3.1 Editionia-32
DebianDebian Linux Version3.1 Editionia-64
DebianDebian Linux Version3.1 Editionm68k
DebianDebian Linux Version3.1 Editionmips
DebianDebian Linux Version3.1 Editionmipsel
DebianDebian Linux Version3.1 Editionppc
DebianDebian Linux Version3.1 Editions-390
DebianDebian Linux Version3.1 Editionsparc
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.193
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N