CVE-2007-2838: High severity Debian Debian Linux vulnerability
Published Jul 3, 2007
·Updated
The populateconns function in src/populateconns.c in GSAMBAD 0.1.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gsambadtmp temporary file.
Affected Software
14 affected components
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
GSAMBAD GSAMBAD=0.1.4
Remediation
Patch Available
Patch Available
Event History
Jul 3, 2007
CVE Published
01:30 AM
Data Sourced
01:30 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2838?
CVE-2007-2838 has a moderate severity level due to the potential for local users to overwrite arbitrary files.
2
How do I fix CVE-2007-2838?
To fix CVE-2007-2838, ensure that the GSAMBAD application is updated to a version that addresses the symlink vulnerability.
3
Who is affected by CVE-2007-2838?
CVE-2007-2838 affects local users of GSAMBAD version 0.1.4 on Debian Linux 4.0.
4
What type of attack is associated with CVE-2007-2838?
CVE-2007-2838 is associated with a symlink attack that exploits the handling of temporary files.
5
What application is vulnerable in CVE-2007-2838?
The vulnerable application in CVE-2007-2838 is GSAMBAD version 0.1.4.