Name | CVE-2005-4534 |
Description | The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1208-1 |
Debian Bugs | 329387 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
bugzilla | source | sarge | 2.16.7-7sarge2 | DSA-1208-1 | ||
bugzilla | source | (unstable) | 2.18 | low | 329387 |
The vulnerable script has been removed in the 2.18 upstream release