CVE detail
CVE-2005-3785 — CVE-2005-3785
Published 2005-11-23 · Modified 2026-06-16 · Vendor gentoo · Product linux_eix · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0110
EPSS probability
exploitation probability, 30d
63.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Second-order symlink vulnerability in eix-sync.in in Ebuild IndeX (eix) before 0.5.0_pre2 allows local users to overwrite arbitrary files via a symlink attack on the exi.X.sync temporary file, which is processed by the diff-eix program.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References