First published: Tue Nov 06 2007(Updated: )
The e_hostname function in commands.c in BitchX 1.1a allows local users to overwrite arbitrary files via a symlink attack on temporary files when using the (1) HOSTNAME or (2) IRCHOST command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bitchx Bitchx | =1.1a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5839 is considered a moderate severity vulnerability due to its ability to allow local users to overwrite arbitrary files.
To fix CVE-2007-5839, users should upgrade to a version of BitchX that does not include this vulnerability, as version 1.1a is affected.
Exploiting CVE-2007-5839 can lead to local users gaining unauthorized access to overwrite sensitive files, potentially resulting in data loss or system compromise.
CVE-2007-5839 primarily affects local users operating BitchX version 1.1a on their systems.
The vulnerability in CVE-2007-5839 is triggered by the HOSTNAME and IRCHOST commands in BitchX.