CVE-2005-0610

N/A Unknown
Published: April 12, 2005 Modified: April 16, 2026
View on NVD

Description

Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, (2) overwrite arbitrary files via temporary files when portupgrade upgrades a port or package, or (3) create arbitrary zero-byte files via the pkgdb.fixme temporary file.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/14903
Source: secteam@freebsd.org
Patch Vendor Advisory
http://www.securityfocus.com/bid/13106
Source: secteam@freebsd.org
Vendor Advisory
http://www.vuxml.org/freebsd/22f00553-a09d-11d9-a788-0001020eed82.html
Source: secteam@freebsd.org
Patch Vendor Advisory
http://secunia.com/advisories/14903
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://www.securityfocus.com/bid/13106
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.vuxml.org/freebsd/22f00553-a09d-11d9-a788-0001020eed82.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory

6 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.1%
17th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

freebsd