Record summary

CVE-2005-1707 has a selected CVSS score of 4.6; EIP currently links 1 catalogued exploit.

Description

The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBGentoo Webapp-Config 1.10 - Insecure File CreationExploitDB exploitby Eric RomangNot analyzed1 file
ExploitDB

PoC details

References

9