gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-07-10 21:00
Updated : 2016-10-17 20:25
NVD link : CVE-2005-2180
Mitre link : CVE-2005-2180
JSON object : View
CWE
Products Affected
gnu
- gnats