CVE-2005-2991

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/09/2005
Last modified:
03/04/2025

Description

ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ncompress:ncompress:*:*:*:*:*:*:*:* 4.2.4_r1 (including)