CVE-2007-5194: Medium severity rPath Rmake vulnerability
Published Oct 4, 2007
·Updated
The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device number as /dev/port, which might allow local users to gain root privileges.
Affected Software
1 affected component
rPath Rmake=1.0.11
Event History
Oct 4, 2007
CVE Published
05:17 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5194?
CVE-2007-5194 is considered a high severity vulnerability due to its potential to allow local users to gain root privileges.
2
How do I fix CVE-2007-5194?
To fix CVE-2007-5194, you should update rMake to a version that does not create the insecure /dev/zero device file.
3
What software is affected by CVE-2007-5194?
CVE-2007-5194 affects rMake version 1.0.11.
4
Who is vulnerable to CVE-2007-5194?
Local users of systems running rMake 1.0.11 are vulnerable to CVE-2007-5194.
5
What type of vulnerability is CVE-2007-5194?
CVE-2007-5194 is a local privilege escalation vulnerability.