VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, creates temporary log files with predictable names, which allows local users to modify arbitrary files via a symlink attack.
References
Link | Resource |
---|---|
http://www.adobe.com/support/techdocs/327129.html | Patch Vendor Advisory |
http://secunia.com/advisories/16541 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/14638 | |
http://securitytracker.com/id?1014776 | |
http://www.idefense.com/application/poi/display?id=297&type=vulnerabilities |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-08-23 21:00
Updated : 2008-09-05 13:50
NVD link : CVE-2005-1842
Mitre link : CVE-2005-1842
JSON object : View
CWE
Products Affected
adobe
- version_cue