CVE-2007-0625: Medium severity NoMachine NX Server vulnerability
Published Jan 31, 2007
·Updated
nxconfigure.sh in NoMachine NX Server before 2.1.0-18 does not validate the invoking user, which allows local users to modify server configuration keys in /usr/NX/etc/server.cfg, resulting in an unspecified denial of service.
Affected Software
1 affected component
NoMachine NX Server<=2.1.0_17
Remediation
Patch Available
Patch Available
Event History
Jan 31, 2007
CVE Published
06:28 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0625?
CVE-2007-0625 has a moderate severity level due to its potential for local denial of service.
2
How do I fix CVE-2007-0625?
To fix CVE-2007-0625, update the NoMachine NX Server to version 2.1.0-18 or later.
3
What causes CVE-2007-0625?
CVE-2007-0625 is caused by nxconfigure.sh not validating the invoking user, allowing unauthorized configuration modifications.
4
What impact does CVE-2007-0625 have on my system?
CVE-2007-0625 can lead to a denial of service on the NoMachine NX Server if exploited by local users.
5
Is CVE-2007-0625 specific to certain versions of NoMachine NX Server?
Yes, CVE-2007-0625 affects NoMachine NX Server versions before 2.1.0-18.