First published: Sat Feb 03 2007(Updated: )
The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Smb4K | =0.4 | |
Smb4K | =0.5 | |
Smb4K | =0.6 | |
Smb4K | =0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0473 has a medium severity level due to its potential for local users to gain access to sensitive information.
To fix CVE-2007-0473, you should upgrade Smb4K to version 0.8.0 or later, which includes the necessary permission fixes.
CVE-2007-0473 affects Smb4K versions 0.4 to 0.7.
CVE-2007-0473 is a local file permissions vulnerability that may expose sensitive system files.
No, CVE-2007-0473 can only be exploited by local users who have access to the system.