First published: Thu Sep 08 2005(Updated: )
smb4k 0.4 and other versions before 0.6.3 allows local users to read sensitive files via a symlink attack on the (1) smb4k.tmp or (2) sudoers temporary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Smb4K | =0.4 | |
Smb4K | =0.5 | |
Smb4K | =0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2851 is considered a medium severity vulnerability as it allows local users to read sensitive files.
To fix CVE-2005-2851, upgrade to Smb4K version 0.6.3 or later to eliminate symlink vulnerabilities.
Users of Smb4K versions 0.4, 0.5, and 0.6 are affected by CVE-2005-2851.
CVE-2005-2851 describes a symlink attack that allows the reading of sensitive files by local users.
Yes, CVE-2005-2851 can lead to unauthorized data exposure through symlink exploitation.