CVE-2007-5827: Low severity Debian Debian Linux vulnerability
Published Nov 5, 2007
·Updated
iSCSI Enterprise Target (iscsitarget) 0.4.15 uses weak permissions for /etc/ietd.conf, which allows local users to obtain passwords.
Affected Software
14 affected components
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
iscsitarget iscsitarget=0.4.15
Event History
Nov 5, 2007
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
07:46 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2007-5827?
CVE-2007-5827 has a moderate severity level due to weak permissions on sensitive configuration files.
2
How do I fix CVE-2007-5827?
To fix CVE-2007-5827, you should change the permissions of /etc/ietd.conf to restrict access to authorized users.
3
Which versions of iSCSI Enterprise Target are affected by CVE-2007-5827?
CVE-2007-5827 affects iSCSI Enterprise Target version 0.4.15.
4
Can local users exploit CVE-2007-5827?
Yes, local users can exploit CVE-2007-5827 to gain access to passwords stored in the improperly secured configuration file.
5
Is CVE-2007-5827 relevant for all Debian installations?
No, CVE-2007-5827 specifically affects Debian Linux installations running iSCSI Enterprise Target version 0.4.15.