MEDIUM · 6.4

CVE-2005-4772

liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitiv...

Vulnerability Description

liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitive files, possibly giving local users the ability to exploit CVE-2005-3013.

CVSS Score

6.4

MEDIUM

AV:N/AC:L/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
SuseSuse Linux Openexchange Server4.0
SuseSuse Linux School Servergold
SuseSuse Linux Standard Server8.0
SuseSuse Sled Beagle10.0
SuseSuse Linux1.0

References

FAQ

What is CVE-2005-4772?

CVE-2005-4772 is a vulnerability with a CVSS score of 6.4 (MEDIUM). liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitiv...

How severe is CVE-2005-4772?

CVE-2005-4772 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-4772?

Check the references section above for vendor advisories and patch information. Affected products include: Suse Suse Linux Openexchange Server, Suse Suse Linux School Server, Suse Suse Linux Standard Server, Suse Suse Sled Beagle, Suse Suse Linux.