Vulnerabilities > CVE-2005-4803 - Unspecified vulnerability in Graphviz
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN graphviz
nessus
Summary
graphviz before 2.2.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files. NOTE: this issue was originally associated with a different CVE identifier, CVE-2005-2965, which had been used for multiple different issues. This is the correct identifier.
Vulnerable Configurations
Nessus
NASL family Mandriva Local Security Checks NASL id MANDRAKE_MDKSA-2005-188.NASL description Javier Fernández-Sanguino Peña discovered insecure temporary file creation in graphviz, a rich set of graph drawing tools, that can be exploited to overwrite arbitrary files by a local attacker. The updated packages have been patched to address this issue. last seen 2020-06-01 modified 2020-06-02 plugin id 20433 published 2006-01-15 reporter This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/20433 title Mandrake Linux Security Advisory : graphviz (MDKSA-2005:188) NASL family Ubuntu Local Security Checks NASL id UBUNTU_USN-208-1.NASL description Javier Fernandez-Sanguino Pena discovered that the last seen 2020-06-01 modified 2020-06-02 plugin id 20625 published 2006-01-15 reporter Ubuntu Security Notice (C) 2005-2019 Canonical, Inc. / NASL script (C) 2006-2016 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/20625 title Ubuntu 5.04 : graphviz vulnerability (USN-208-1) NASL family Debian Local Security Checks NASL id DEBIAN_DSA-857.NASL description Javier Fernandez-Sanguino Pena discovered insecure temporary file creation in graphviz, a rich set of graph drawing tools, that can be exploited to overwrite arbitrary files by a local attacker. last seen 2020-06-01 modified 2020-06-02 plugin id 19965 published 2005-10-11 reporter This script is Copyright (C) 2005-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/19965 title Debian DSA-857-1 : graphviz - insecure temporary file
References
- http://secunia.com/advisories/17121
- http://secunia.com/advisories/17121
- http://secunia.com/advisories/17125
- http://secunia.com/advisories/17125
- http://secunia.com/advisories/17207
- http://secunia.com/advisories/17207
- http://www.debian.org/security/2005/dsa-857
- http://www.debian.org/security/2005/dsa-857
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:188
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:188
- http://www.securityfocus.com/bid/15050
- http://www.securityfocus.com/bid/15050
- https://usn.ubuntu.com/208-1/
- https://usn.ubuntu.com/208-1/