CVE-2007-3912: Input Validation
Published Sep 10, 2007
·Updated
checkrestart in debian-goodies before 0.34 allows local users to gain privileges via shell metacharacters in the name of the executable file for a running process.
Affected Software
2 affected components
Debian debian-goodies=0.27
Debian debian-goodies=0.33
Remediation
Patch Available
Event History
Sep 10, 2007
CVE Published
05:17 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3912?
CVE-2007-3912 is classified as a high severity vulnerability due to its ability to enable local users to gain elevated privileges.
2
How do I fix CVE-2007-3912?
To fix CVE-2007-3912, users should upgrade to Debian-goodies version 0.34 or later.
3
Who is affected by CVE-2007-3912?
Users of Debian-goodies versions 0.27 and 0.33 are affected by CVE-2007-3912.
4
What type of vulnerability is CVE-2007-3912?
CVE-2007-3912 is a local privilege escalation vulnerability.
5
What can attackers do with CVE-2007-3912?
Attackers can exploit CVE-2007-3912 to execute arbitrary code with elevated privileges by manipulating the executable file names.