CVE-2005-4691 describes a local file overwrite vulnerability in imake, affecting NetBSD versions prior to 2.0.3, NetBSD-current before September 12, 2005, and certain X.Org and XFree86 versions. An attacker could exploit this by using a symlink attack on a temporary file to overwrite arbitrary files, specifically targeting the file.0 target used for pre-formatted manual pages. With a CVSS score of 2.1 (low severity), this vulnerability requires local access and has a low attack complexity, primarily impacting integrity with no confidentiality or availability concerns. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6CPE matchmatch criteria | cpe:2.3:o:netbsd:netbsd:1.6:*:*:*:*:*:*:* | ||
1.6CPE matchmatch criteria | cpe:2.3:o:netbsd:netbsd:1.6:beta:*:*:*:*:*:* | ||
1.6.1CPE matchmatch criteria | cpe:2.3:o:netbsd:netbsd:1.6.1:*:*:*:*:*:*:* | ||
1.6.2CPE matchmatch criteria | cpe:2.3:o:netbsd:netbsd:1.6.2:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:o:netbsd:netbsd:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.