CVE-2007-2030: Medium severity redhat Enterprise Linux vulnerability
Published Apr 16, 2007
·Updated
lharc.c in lha does not securely create temporary files, which might allow local users to read or write files by creating a file before LHA is invoked.
Affected Software
4 affected components
redhat Enterprise Linux=2.1
redhat Enterprise Linux=3.0
redhat Enterprise Linux=4.0
redhat Fedora Core=core_5.0
Event History
Apr 16, 2007
CVE Published
08:19 PM
Apr 17, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2030?
CVE-2007-2030 has a moderate severity rating due to its potential to allow local users to manipulate files.
2
How do I fix CVE-2007-2030?
To mitigate CVE-2007-2030, ensure that the lha tool properly manages temporary file creation by using secure methods.
3
What software versions are affected by CVE-2007-2030?
CVE-2007-2030 affects Red Hat Enterprise Linux versions 2.1, 3.0, 4.0, and Red Hat Fedora Core 5.0.
4
Can CVE-2007-2030 be exploited remotely?
CVE-2007-2030 cannot be exploited remotely as it requires local access to the system.
5
What are the risks associated with CVE-2007-2030?
The risks include unauthorized reading or writing of files by local users due to insecure temporary file handling.