CVE-2005-2945
arc - insecure temporary file
EPSS 0.36%
Description
arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) marc (marc.c).
How to fix CVE-2005-2945
To remediate CVE-2005-2945, upgrade the affected package to a fixed version below.
- Debian/arc—upgrade to 5.21m-1 or later
- Debian/arc—upgrade to 5.21l-1sarge1 or later
Is CVE-2005-2945 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 5.21m-1
- from 0, < 5.21l-1sarge1