CVE-2005-2992

NameCVE-2005-2992
Descriptionarc 5.21j and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different type of vulnerability than CVE-2005-2945.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-843-1
NVD severitylow (attack range: local)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
arc (PTS)wheezy5.21p-1fixed
jessie5.21q-1fixed
buster, sid, stretch5.21q-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
arcsource(unstable)5.21m-1low
arcsourcesarge5.21l-1sarge1lowDSA-843-1

Search for package or bug name: Reporting problems