Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.
CVSS Details
- CVSS 3.1 Base Score: 4.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade shtoolUpgrade mysql-ocaml | Jul 30, 2024 | May 25, 2005 |
| Gentoo Linux | — | Upgrade dev-ml/ocaml-mysql.Upgrade dev-util/shtool. | Oct 30, 2017 | May 25, 2005 |
| Ubuntu | — | Upgrade php4-pear | Nov 8, 2024 | May 25, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub