The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.
References
Configurations
History
No history.
Information
Published : 2007-10-30 19:46
Updated : 2024-02-04 17:13
NVD link : CVE-2007-5714
Mitre link : CVE-2007-5714
CVE.ORG link : CVE-2007-5714
JSON object : View
Products Affected
gentoo
- mldonkey_ebuild
CWE
CWE-287
Improper Authentication