mirrorselect before 0.89 creates temporary files in a world-writable location with predictable file names, which allows remote attackers to overwrite arbitrary files via a symlink attack.
2005-01-10T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gentoo | mirrorselect | 0.80 | Yes |
Application | gentoo | mirrorselect | 0.81 | Yes |
Application | gentoo | mirrorselect | 0.82 | Yes |
Application | gentoo | mirrorselect | 0.83 | Yes |
Application | gentoo | mirrorselect | 0.84 | Yes |
Application | gentoo | mirrorselect | 0.85 | Yes |
Application | gentoo | mirrorselect | 0.86 | Yes |
Application | gentoo | mirrorselect | 0.87 | Yes |
Application | gentoo | mirrorselect | 0.88 | Yes |