{"api_version":"1","generated_at":"2026-07-23T12:03:42+00:00","cve":"CVE-2005-2657","urls":{"html":"https://cve.report/CVE-2005-2657","api":"https://cve.report/api/cve/CVE-2005-2657.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2657","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2657"},"summary":{"title":"CVE-2005-2657","description":"Unknown vulnerability in common-lisp-controller 4.18 and earlier allows local users to gain privileges by compiling arbitrary code in the cache directory, which is executed by another user if the user has not run Common Lisp before.","state":"PUBLISHED","assigner":"debian","published_at":"2005-09-16 22:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.debian.org/security/2005/dsa-811","name":"http://www.debian.org/security/2005/dsa-811","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Debian -- Security Information -- DSA-811-2 common-lisp-controller","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/16822/","name":"http://secunia.com/advisories/16822/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - common-lisp-controller Cache Directory Privilege Escalation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22275","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22275","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/14829","name":"http://www.securityfocus.com/bid/14829","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Common-Lisp-Controller Cache Arbitrary Code Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2657","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2657","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2657","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"common-lisp-controller","cpe5":"common-lisp-controller","cpe6":"4.18","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:45:01.332Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"common-lisp-controller-cache-gain-priv(22275)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22275"},{"name":"16822","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/16822/"},{"name":"14829","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14829"},{"name":"DSA-811","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2005/dsa-811"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-09-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unknown vulnerability in common-lisp-controller 4.18 and earlier allows local users to gain privileges by compiling arbitrary code in the cache directory, which is executed by another user if the user has not run Common Lisp before."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"79363d38-fa19-49d1-9214-5f28da3f3ac5","shortName":"debian"},"references":[{"name":"common-lisp-controller-cache-gain-priv(22275)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22275"},{"name":"16822","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/16822/"},{"name":"14829","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14829"},{"name":"DSA-811","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2005/dsa-811"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@debian.org","ID":"CVE-2005-2657","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unknown vulnerability in common-lisp-controller 4.18 and earlier allows local users to gain privileges by compiling arbitrary code in the cache directory, which is executed by another user if the user has not run Common Lisp before."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"common-lisp-controller-cache-gain-priv(22275)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22275"},{"name":"16822","refsource":"SECUNIA","url":"http://secunia.com/advisories/16822/"},{"name":"14829","refsource":"BID","url":"http://www.securityfocus.com/bid/14829"},{"name":"DSA-811","refsource":"DEBIAN","url":"http://www.debian.org/security/2005/dsa-811"}]}}}},"cveMetadata":{"assignerOrgId":"79363d38-fa19-49d1-9214-5f28da3f3ac5","assignerShortName":"debian","cveId":"CVE-2005-2657","datePublished":"2005-09-16T04:00:00.000Z","dateReserved":"2005-08-22T00:00:00.000Z","dateUpdated":"2024-08-07T22:45:01.332Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-09-16 22:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:common-lisp-controller:common-lisp-controller:4.18:*:*:*:*:*:*:*","matchCriteriaId":"DD357A83-5979-44BD-B96B-E53736808F15"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2657","Ordinal":"1","Title":"CVE-2005-2657","CVE":"CVE-2005-2657","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2657","Ordinal":"1","NoteData":"Unknown vulnerability in common-lisp-controller 4.18 and earlier allows local users to gain privileges by compiling arbitrary code in the cache directory, which is executed by another user if the user has not run Common Lisp before.","Type":"Description","Title":"CVE-2005-2657"},{"CveYear":"2005","CveId":"2657","Ordinal":"2","NoteData":"2005-09-16","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2657","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}