CVE Vulnerabilities

CVE-2007-0472

Published: Feb 03, 2007 | Modified: Mar 08, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Multiple race conditions in Smb4K before 0.8.0 allow local users to (1) modify arbitrary files via unspecified manipulations of Smb4Ks lock file, which is not properly handled by the remove_lock_file function in core/smb4kfileio.cpp, and (2) add lines to the sudoers file via a symlink attack on temporary files, which isnt properly handled by the writeFile function in core/smb4kfileio.cpp.

Affected Software

Name Vendor Start Version End Version
Smb4k Smb4k 0.4 (including) 0.4 (including)
Smb4k Smb4k 0.5 (including) 0.5 (including)
Smb4k Smb4k 0.6 (including) 0.6 (including)
Smb4k Smb4k 0.7 (including) 0.7 (including)
Smb4k Ubuntu dapper *
Smb4k Ubuntu edgy *
Smb4k Ubuntu feisty *
Smb4k Ubuntu upstream *

References