CVE-2005-2960

Publication date 5 October 2005

Last updated 17 July 2025


Ubuntu priority

cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by vicf.in, a different vulnerability than CVE-2005-3137.

Status

Package Ubuntu Release Status
cfengine 7.04 feisty Not in release
6.10 edgy
Fixed 1.6.5-2ubuntu1
6.06 LTS dapper
Fixed 1.6.5-2ubuntu1

References

Related Ubuntu Security Notices (USN)

    • USN-198-1
    • cfengine vulnerabilities
    • 10 October 2005

Other references