First published: Sat Aug 11 2007(Updated: )
CoolKey 1.1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files in the /tmp/.pk11ipc1/ directory.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/coolkey | <0:1.1.0-5.el5 | 0:1.1.0-5.el5 |
Red Hat Enterprise Linux | =5.0 | |
Red Hat Enterprise Linux | =5.0 | |
Red Hat Enterprise Linux | =5.0 | |
Fedora | =1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4129 has a medium severity rating due to the potential for local users to overwrite arbitrary files.
To fix CVE-2007-4129, update CoolKey to a version newer than 1.1.0 or apply any available security patches.
CVE-2007-4129 affects local users on systems running CoolKey version 1.1.0.
CVE-2007-4129 allows local users to conduct symlink attacks to overwrite arbitrary files.
CVE-2007-4129 was disclosed in 2007.