CVE-2007-0472

Multiple race conditions in Smb4K before 0.8.0 allow local users to (1) modify arbitrary files via unspecified manipulations of Smb4K's lock file, which is not properly handled by the remove_lock_file function in core/smb4kfileio.cpp, and (2) add lines to the sudoers file via a symlink attack on temporary files, which isn't properly handled by the writeFile function in core/smb4kfileio.cpp.
References
Link Resource
http://developer.berlios.de/bugs/?func=detailbug&bug_id=9630&group_id=769
http://developer.berlios.de/project/shownotes.php?release_id=11706
http://developer.berlios.de/project/shownotes.php?release_id=11902
http://developer.berlios.de/project/shownotes.php?release_id=9777
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html
http://secunia.com/advisories/23937 Patch Vendor Advisory
http://secunia.com/advisories/23984
http://secunia.com/advisories/24111
http://secunia.com/advisories/24469
http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:042
http://www.securityfocus.com/bid/22299
http://www.vupen.com/english/advisories/2007/0393
https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html Patch
http://developer.berlios.de/bugs/?func=detailbug&bug_id=9630&group_id=769
http://developer.berlios.de/project/shownotes.php?release_id=11706
http://developer.berlios.de/project/shownotes.php?release_id=11902
http://developer.berlios.de/project/shownotes.php?release_id=9777
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html
http://secunia.com/advisories/23937 Patch Vendor Advisory
http://secunia.com/advisories/23984
http://secunia.com/advisories/24111
http://secunia.com/advisories/24469
http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:042
http://www.securityfocus.com/bid/22299
http://www.vupen.com/english/advisories/2007/0393
https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:smb4k:smb4k:0.4:*:*:*:*:*:*:*
cpe:2.3:a:smb4k:smb4k:0.5:*:*:*:*:*:*:*
cpe:2.3:a:smb4k:smb4k:0.6:*:*:*:*:*:*:*
cpe:2.3:a:smb4k:smb4k:0.7:*:*:*:*:*:*:*

History

21 Nov 2024, 00:25

Type Values Removed Values Added
References () http://developer.berlios.de/bugs/?func=detailbug&bug_id=9630&group_id=769 - () http://developer.berlios.de/bugs/?func=detailbug&bug_id=9630&group_id=769 -
References () http://developer.berlios.de/project/shownotes.php?release_id=11706 - () http://developer.berlios.de/project/shownotes.php?release_id=11706 -
References () http://developer.berlios.de/project/shownotes.php?release_id=11902 - () http://developer.berlios.de/project/shownotes.php?release_id=11902 -
References () http://developer.berlios.de/project/shownotes.php?release_id=9777 - () http://developer.berlios.de/project/shownotes.php?release_id=9777 -
References () http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html - () http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html -
References () http://secunia.com/advisories/23937 - Patch, Vendor Advisory () http://secunia.com/advisories/23937 - Patch, Vendor Advisory
References () http://secunia.com/advisories/23984 - () http://secunia.com/advisories/23984 -
References () http://secunia.com/advisories/24111 - () http://secunia.com/advisories/24111 -
References () http://secunia.com/advisories/24469 - () http://secunia.com/advisories/24469 -
References () http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml - () http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2007:042 - () http://www.mandriva.com/security/advisories?name=MDKSA-2007:042 -
References () http://www.securityfocus.com/bid/22299 - () http://www.securityfocus.com/bid/22299 -
References () http://www.vupen.com/english/advisories/2007/0393 - () http://www.vupen.com/english/advisories/2007/0393 -
References () https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html - Patch () https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html - Patch

Information

Published : 2007-02-03 23:28

Updated : 2024-11-21 00:25


NVD link : CVE-2007-0472

Mitre link : CVE-2007-0472

CVE.ORG link : CVE-2007-0472


JSON object : View

Products Affected

smb4k

  • smb4k