security flaw
Published Sep 21, 2005
1.2
LOWCVSS 2.0
EPSS 0.51%
Description
The sort_offline function for texindex in texinfo 4.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Affected products
No data.
No data.
Red Hat Enterprise Linux 2.1
texinfo-0:4.0b-3.el2.1
Fixed · RHSA-2006:0727
Red Hat Enterprise Linux 3
texinfo-0:4.5-3.el3.1
Fixed · RHSA-2006:0727
Red Hat Enterprise Linux 4
texinfo-0:4.7-5.el4.2
Fixed · RHSA-2006:0727
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | texinfo-0:4.0b-3.el2.1 | Fixed | RHSA-2006:0727 |
| Red Hat Enterprise Linux 3 | texinfo-0:4.5-3.el3.1 | Fixed | RHSA-2006:0727 |
| Red Hat Enterprise Linux 4 | texinfo-0:4.7-5.el4.2 | Fixed | RHSA-2006:0727 |
No package ranges for this CVE.
Remediation
Red Hat statement
Updated packages to correct this issue are available along with our advisory: http://rhn.redhat.com/errata/CVE-2005-3011.html Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:H/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.51% (0.00505) | 40.93th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.51% (0.00505) | 38.95th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.04% (0.00043) | 10.38th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.06% (0.00064) | 30.04th | v3 (v2023.03.01) |
| Jun 21, 2024 | 0.06% (0.00064) | 28.12th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00064) | 26.10th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
References (36)
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:01.texindex.asc vendor-advisoryx_refsource_FREEBSD
- ftp://patches.sgi.com/support/free/security/advisories/20061101-01-P vendor-advisoryx_refsource_SGI
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=328365 x_refsource_MISCExploit
- http://docs.info.apple.com/article.html?artnum=305530 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2007/May/msg00004.html vendor-advisoryx_refsource_APPLE
- http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html vendor-advisoryx_refsource_TRUSTIX
- http://secunia.com/advisories/16816 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/17070 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/17076 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/17093 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/17211 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/17215 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18401 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22929 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23112 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/24788 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/25402 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1014992 vdb-entryx_refsource_SECTRACK
- http://securitytracker.com/id?1015468 vdb-entryx_refsource_SECTRACK
- http://www.debian.org/security/2006/dsa-1219 vendor-advisoryx_refsource_DEBIAN
- http://www.gentoo.org/security/en/glsa/glsa-200510-04.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:175 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2005_23_sr.html vendor-advisoryx_refsource_SUSE
- http://www.redhat.com/support/errata/RHSA-2006-0727.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/464745/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/14854 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-194-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vmware.com/support/vi3/doc/esx-1121906-patch.html x_refsource_CONFIRM
- http://www.vmware.com/support/vi3/doc/esx-2559638-patch.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2007/1267 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2007/1939 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2005-3011 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1617775 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2005-3011
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10589 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2005-3011
Change history (0)
No recorded changes yet.