Vulnerability Report

CVE-2005-3546

Title: F-Secure suid.cgi SUID world-executable scripts allow privilege gain

Other

Proof Of Concept

PoC Available for CVE-2005-3546

CWE Category NVD-CWE-noinfo
Published Date Nov 16, 2005
Modified Date Jun 16, 2026
Exploit Status Available
Score 7.2 CVSS v2.0
Exploit Probability (EPSS)
0.80%

Vulnerability Summary

CVE-2005-3546: suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.

Impacted Vendors

Reference Links

http://secunia.com/advisories/17467 http://securitytracker.com/id?1015159 http://securitytracker.com/id?1015160 http://www.f-secure.com/security/fsc-2005-3.shtml http://www.osvdb.org/20513 http://www.osvdb.org/20537 http://www.osvdb.org/20538 http://www.osvdb.org/20539 http://www.osvdb.org/20540 http://www.osvdb.org/20541 http://www.osvdb.org/20542 http://www.osvdb.org/20543 http://www.osvdb.org/20544 http://www.osvdb.org/20545 http://www.osvdb.org/20546 http://www.osvdb.org/20547 http://www.osvdb.org/20548 http://www.osvdb.org/20549 http://www.osvdb.org/20550 http://www.osvdb.org/20551 http://www.osvdb.org/20552 http://www.securityfocus.com/bid/15339 http://www.vupen.com/english/advisories/2005/2331 https://exchange.xforce.ibmcloud.com/vulnerabilities/22966 http://secunia.com/advisories/17467 http://securitytracker.com/id?1015159 http://securitytracker.com/id?1015160 http://www.f-secure.com/security/fsc-2005-3.shtml http://www.osvdb.org/20513 http://www.osvdb.org/20537 http://www.osvdb.org/20538 http://www.osvdb.org/20539 http://www.osvdb.org/20540 http://www.osvdb.org/20541 http://www.osvdb.org/20542 http://www.osvdb.org/20543 http://www.osvdb.org/20544 http://www.osvdb.org/20545 http://www.osvdb.org/20546 http://www.osvdb.org/20547 http://www.osvdb.org/20548 http://www.osvdb.org/20549 http://www.osvdb.org/20550 http://www.osvdb.org/20551 http://www.osvdb.org/20552 http://www.securityfocus.com/bid/15339 http://www.vupen.com/english/advisories/2005/2331 https://exchange.xforce.ibmcloud.com/vulnerabilities/22966
CVSS v2.0
Source Entity [email protected]
Severity HIGH
7.2
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:L/AC:L/Au:N/C:C/I:C/A:C

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2005-3546 Exploits & PoCs (Proof Of Concept)

Exploit-DB https://www.exploit-db.com/exploits/1297
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected Stack

No specific products linked.