FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-1111

This CVE name corresponds to:

Entered Topic
2006-01-27 cpio -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-1111
Phase Assigned(20050416)

Description

Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.

References

Source Reference
BUGTRAQ 20050413 cpio TOCTOU file-permissions vulnerability
DEBIAN DSA-846
FREEBSD FreeBSD-SA-06:03
REDHAT RHSA-2005:806
REDHAT RHSA-2005:378
SCO SCOSA-2005.32
SCO SCOSA-2006.2
SUSE SUSE-SR:2006:010
UBUNTU USN-189-1
BID 13159
OSVDB 15725
OVAL oval:org.mitre.oval:def:358
OVAL oval:org.mitre.oval:def:9783
SECUNIA 18290
SECUNIA 18395
SECUNIA 17123
SECUNIA 17532
SECUNIA 16998
SECUNIA 20117