security flaw
Published Aug 25, 2005
4.6
MEDIUMCVSS 2.0
EPSS 0.44%
Description
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
Affected products
No data.
No data.
Red Hat Enterprise Linux 3
cvs-0:1.11.2-28
Fixed · RHSA-2005:756
Red Hat Enterprise Linux 4
cvs-0:1.11.17-8.RHEL4
Fixed · RHSA-2005:756
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | cvs-0:1.11.2-28 | Fixed | RHSA-2005:756 |
| Red Hat Enterprise Linux 4 | cvs-0:1.11.17-8.RHEL4 | Fixed | RHSA-2005:756 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.44% (0.00443) | 36.16th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.44% (0.00443) | 35.03th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.08% (0.00083) | 21.82th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00047) | 19.21th | v3 (v2023.03.01) |
| May 8, 2024 | 0.05% (0.00047) | 16.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00047) | 14.21th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.17% (0.02172) | 80.27th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.17% (0.02172) | 78.34th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.17% (0.02172) | 57.15th | v2 (v2022.01.01) |
No CWE recorded.
References (13)
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:20.cvsbug.asc vendor-advisoryx_refsource_FREEBSD
- http://secunia.com/advisories/16765 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1014857 vdb-entryx_refsource_SECTRACK
- http://www.debian.org/security/2005/dsa-802 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2005/dsa-806 vendor-advisoryx_refsource_DEBIAN
- http://www.redhat.com/support/errata/RHSA-2005-756.html vendor-advisoryx_refsource_REDHAT
- http://www.vupen.com/english/advisories/2005/1667 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2005-2693 Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166366 x_refsource_CONFIRMPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=1617740 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2005-2693
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10835 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2005-2693
Change history (0)
No recorded changes yet.