CVE-2005-2807: High severity frox vulnerability
Published Sep 7, 2005
·Updated
frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.
Affected Software
1 affected component
frox frox=0.7.18
Event History
Sep 7, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2807?
CVE-2005-2807 is considered a medium severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2005-2807?
To fix CVE-2005-2807, upgrade to frox version 0.7.19 or later, where privilege dropping has been implemented correctly.
3
What type of vulnerability is CVE-2005-2807?
CVE-2005-2807 is a local privilege escalation vulnerability affecting frox when it runs with setuid root.
4
Who is affected by CVE-2005-2807?
Local users on a system running frox version 0.7.18 with setuid root privileges are affected by CVE-2005-2807.
5
Can attackers exploit CVE-2005-2807 remotely?
No, CVE-2005-2807 requires local access to the system to be exploited.