ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.
References
Configurations
Information
Published : 2005-09-20 13:03
Updated : 2016-10-17 20:32
NVD link : CVE-2005-2991
Mitre link : CVE-2005-2991
JSON object : View
CWE
Products Affected
ncompress
- ncompress