The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does...
Vulnerability Description
The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-0473
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/23984
- https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html
- http://developer.berlios.de/project/shownotes.php?release_id=9777
- http://www.securityfocus.com/bid/22299
- http://secunia.com/advisories/24111
- http://secunia.com/advisories/24469
- http://www.vupen.com/english/advisories/2007/0393
- http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml
- http://secunia.com/advisories/23937
- http://developer.berlios.de/project/shownotes.php?release_id=11902
- http://developer.berlios.de/project/shownotes.php?release_id=11706
- http://developer.berlios.de/bugs/?func=detailbug&bug_id=9630&group_id=769
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:042
More from smb4k
View All →Affected Vendor
smb4k
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.