First published: Mon Sep 24 2007(Updated: )
The main function in skkdic-expr.c in SKK Tools 1.2 allows local users to overwrite or delete arbitrary files via a symlink attack on a skkdic$PID temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Skk | =1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3916 has a moderate severity level due to its potential to allow local users to overwrite or delete arbitrary files.
To mitigate CVE-2007-3916, ensure that users do not have write access to directories where temporary files are created or apply patches provided by the maintainer.
CVE-2007-3916 affects local users of SKK Tools version 1.2 who can exploit symlink vulnerabilities.
CVE-2007-3916 relates to a symlink attack which could allow unauthorized file manipulation.
No, CVE-2007-3916 is a local vulnerability that requires access to the target machine to exploit.