smb4k 0.4 and other versions before 0.6.3 allows local users to read sensitive files via a symlink attack on the (1) smb4k.tmp or (2) sudoers temporary files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Smb4k | Smb4k | 0.4 (including) | 0.4 (including) |
Smb4k | Smb4k | 0.5 (including) | 0.5 (including) |
Smb4k | Smb4k | 0.6 (including) | 0.6 (including) |
Smb4k | Ubuntu | dapper | * |
Smb4k | Ubuntu | devel | * |
Smb4k | Ubuntu | edgy | * |
Smb4k | Ubuntu | feisty | * |
Smb4k | Ubuntu | gutsy | * |
Smb4k | Ubuntu | upstream | * |