First published: Thu Oct 04 2007(Updated: )
The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device number as /dev/port, which might allow local users to gain root privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rpath Rmake | =1.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5194 is considered a high severity vulnerability due to its potential to allow local users to gain root privileges.
To fix CVE-2007-5194, you should update rMake to a version that does not create the insecure /dev/zero device file.
CVE-2007-5194 affects rMake version 1.0.11.
Local users of systems running rMake 1.0.11 are vulnerable to CVE-2007-5194.
CVE-2007-5194 is a local privilege escalation vulnerability.