2.1

CVE-2006-0055

The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.

Data is provided by the National Vulnerability Database (NVD)
FreebsdFreebsd Version4.10
FreebsdFreebsd Version4.10 Updaterelease
FreebsdFreebsd Version4.10 Updaterelease_p8
FreebsdFreebsd Version4.10 Updatereleng
FreebsdFreebsd Version4.11 Updaterelease_p3
FreebsdFreebsd Version4.11 Updatereleng
FreebsdFreebsd Version4.11 Updatestable
FreebsdFreebsd Version5.0
FreebsdFreebsd Version5.0 Updatealpha
FreebsdFreebsd Version5.0 Updaterelease_p14
FreebsdFreebsd Version5.0 Updatereleng
FreebsdFreebsd Version5.1
FreebsdFreebsd Version5.1 Updatealpha
FreebsdFreebsd Version5.1 Updaterelease
FreebsdFreebsd Version5.1 Updaterelease_p5
FreebsdFreebsd Version5.1 Updatereleng
FreebsdFreebsd Version5.2
FreebsdFreebsd Version5.2.1 Updaterelease
FreebsdFreebsd Version5.2.1 Updatereleng
FreebsdFreebsd Version5.3
FreebsdFreebsd Version5.3 Updaterelease
FreebsdFreebsd Version5.3 Updatereleng
FreebsdFreebsd Version5.3 Updatestable
FreebsdFreebsd Version5.4 Updatepre-release
FreebsdFreebsd Version5.4 Updaterelease
FreebsdFreebsd Version5.4 Updatereleng
FreebsdFreebsd Version6.0 Updaterelease
FreebsdFreebsd Version6.0 Updatestable
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.19
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N