The (1) kantiword (kantiword.sh) and (2) gantiword (gantiword.sh) scripts in antiword 0.35 and earlier allow local users to overwrite arbitrary files via a symlink attack on temporary (a) output and (b) error files.
References
Link | Resource |
---|---|
http://secunia.com/advisories/15866 | Vendor Advisory |
http://secunia.com/advisories/18530 | Patch Vendor Advisory |
http://www.debian.org/security/2005/dsa-945 | |
http://www.securityfocus.com/bid/16278 | |
http://www.vupen.com/english/advisories/2006/0242 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24194 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: debian
Published: 2006-01-18T00:00:00
Updated: 2017-07-10T14:57:01
Reserved: 2005-10-03T00:00:00
Link: CVE-2005-3126
JSON object: View
NVD Information
Status : Modified
Published: 2005-12-31T05:00:00.000
Modified: 2017-07-11T01:33:06.157
Link: CVE-2005-3126
JSON object: View
Redhat Information
No data.
CWE