2.1
CVE-2005-3268
- EPSS 0.4%
- Veröffentlicht 20.10.2005 23:02:00
- Zuletzt bearbeitet 16.06.2026 22:16:36
- Quelle security@debian.org
- CVE-Watchlists
- Unerledigt
yiff server (yiff-server) 2.14.2 on Debian GNU/Linux runs as root and does not properly verify ownership of files that it opens, which allows local users to read arbitrary files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Raphael Bossek ≫ Yiff Server Version2.14.2.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.312 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=334616
http://secunia.com/advisories/17242
http://www.osvdb.org/20074
http://www.securityfocus.com/bid/15140