Title : FreeBSD Security Update Fixes Eeasy Editor (ee) Temporary File Issue VUPEN ID : VUPEN/ADV-2006-0141 CVE ID : CVE-2006-0055
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-01-11
Technical Description
FreeBSD has released security patches to address a vulnerability identified in Eeasy Editor (ee). This flaw is due to an error in the "ispell_op()" function that creates temporary files in an insecure manner when executing spell check operations, which could be exploited by local attackers to overwrite arbitrary files with the privileges of the user running the vulnerable utility.
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.