First published: Sun Oct 14 2007(Updated: )
hugin, as used on various operating systems including SUSE openSUSE 10.2 and 10.3, allows local users to overwrite arbitrary files via a symlink attack on the hugin_debug_optim_results.txt temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/0.6.1 | <11. | 11. |
SUSE Linux | =10.2 | |
SUSE Linux | =10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5200 is considered to be of medium severity due to the potential for local users to manipulate files.
To fix CVE-2007-5200, users should upgrade to the patched version of hugin available for their operating system.
CVE-2007-5200 affects hugin versions in SUSE openSUSE 10.2 and 10.3 as well as specific versions used in Red Hat distributions.
CVE-2007-5200 is associated with a symlink attack that allows local users to overwrite arbitrary files.
A temporary workaround for CVE-2007-5200 is to restrict local user access or set proper file permissions for sensitive files.