CVE-2005-3885

Description

The ps2epsi extension shell script (ps2epsi.sh) in Inkscape before 0.41 allows local users to overwrite arbitrary files via a symlink attack on the tmpepsifile.epsi temporary file.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.079

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Inkscape (EXE) (x64) 0.41Windows
Multiple Vulnerabilities are affected in Inkscape (EXE) 0.41Windows
Multiple Vulnerabilities are affected in Inkscape (x64) 0.41Windows
Multiple Vulnerabilities are affected in Inkscape 0.41Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-334412Inkscape (EXE) (x64) (1.3.1)
PATCH-334562Inkscape (EXE) (1.3.2)
PATCH-342179Inkscape (x64) (1.4)
PATCH-334561Inkscape (1.3.2)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234