The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Smb4k | Smb4k | 0.4 (including) | 0.4 (including) |
Smb4k | Smb4k | 0.5 (including) | 0.5 (including) |
Smb4k | Smb4k | 0.6 (including) | 0.6 (including) |
Smb4k | Smb4k | 0.7 (including) | 0.7 (including) |
Smb4k | Ubuntu | dapper | * |
Smb4k | Ubuntu | edgy | * |
Smb4k | Ubuntu | feisty | * |
Smb4k | Ubuntu | upstream | * |