CVE-2007-0473

The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.
References
Link Resource
http://developer.berlios.de/bugs/?func=detailbug&bug_id=9630&group_id=769
http://developer.berlios.de/project/shownotes.php?release_id=11706
http://developer.berlios.de/project/shownotes.php?release_id=11902
http://developer.berlios.de/project/shownotes.php?release_id=9777
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html
http://secunia.com/advisories/23937 Patch Vendor Advisory
http://secunia.com/advisories/23984
http://secunia.com/advisories/24111
http://secunia.com/advisories/24469
http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:042
http://www.securityfocus.com/bid/22299
http://www.vupen.com/english/advisories/2007/0393
https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html Patch
http://developer.berlios.de/bugs/?func=detailbug&bug_id=9630&group_id=769
http://developer.berlios.de/project/shownotes.php?release_id=11706
http://developer.berlios.de/project/shownotes.php?release_id=11902
http://developer.berlios.de/project/shownotes.php?release_id=9777
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html
http://secunia.com/advisories/23937 Patch Vendor Advisory
http://secunia.com/advisories/23984
http://secunia.com/advisories/24111
http://secunia.com/advisories/24469
http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:042
http://www.securityfocus.com/bid/22299
http://www.vupen.com/english/advisories/2007/0393
https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:smb4k:smb4k:0.4:*:*:*:*:*:*:*
cpe:2.3:a:smb4k:smb4k:0.5:*:*:*:*:*:*:*
cpe:2.3:a:smb4k:smb4k:0.6:*:*:*:*:*:*:*
cpe:2.3:a:smb4k:smb4k:0.7:*:*:*:*:*:*:*

History

21 Nov 2024, 00:25

Type Values Removed Values Added
References () http://developer.berlios.de/bugs/?func=detailbug&bug_id=9630&group_id=769 - () http://developer.berlios.de/bugs/?func=detailbug&bug_id=9630&group_id=769 -
References () http://developer.berlios.de/project/shownotes.php?release_id=11706 - () http://developer.berlios.de/project/shownotes.php?release_id=11706 -
References () http://developer.berlios.de/project/shownotes.php?release_id=11902 - () http://developer.berlios.de/project/shownotes.php?release_id=11902 -
References () http://developer.berlios.de/project/shownotes.php?release_id=9777 - () http://developer.berlios.de/project/shownotes.php?release_id=9777 -
References () http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html - () http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html -
References () http://secunia.com/advisories/23937 - Patch, Vendor Advisory () http://secunia.com/advisories/23937 - Patch, Vendor Advisory
References () http://secunia.com/advisories/23984 - () http://secunia.com/advisories/23984 -
References () http://secunia.com/advisories/24111 - () http://secunia.com/advisories/24111 -
References () http://secunia.com/advisories/24469 - () http://secunia.com/advisories/24469 -
References () http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml - () http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2007:042 - () http://www.mandriva.com/security/advisories?name=MDKSA-2007:042 -
References () http://www.securityfocus.com/bid/22299 - () http://www.securityfocus.com/bid/22299 -
References () http://www.vupen.com/english/advisories/2007/0393 - () http://www.vupen.com/english/advisories/2007/0393 -
References () https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html - Patch () https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html - Patch

Information

Published : 2007-02-03 23:28

Updated : 2024-11-21 00:25


NVD link : CVE-2007-0473

Mitre link : CVE-2007-0473

CVE.ORG link : CVE-2007-0473


JSON object : View

Products Affected

smb4k

  • smb4k