| Vulnerability Name: | CVE-2007-1500 (CCN-33057) | ||||||||
| Assigned: | 2007-03-18 | ||||||||
| Published: | 2007-03-18 | ||||||||
| Updated: | 2017-07-29 | ||||||||
| Summary: | The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat. | ||||||||
| CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
2.3 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | File Manipulation | ||||||||
| References: | Source: MISC Type: UNKNOWN http://bugs.gentoo.org/show_bug.cgi?id=159542 Source: MITRE Type: CNA CVE-2007-1500 Source: OSVDB Type: UNKNOWN 34267 Source: CCN Type: SA24526 Gentoo lsat Insecure Temporary File Creation Source: SECUNIA Type: Vendor Advisory 24526 Source: GENTOO Type: UNKNOWN GLSA-200703-20 Source: CCN Type: GLSA-200703-20 LSAT: Insecure temporary file creation Source: CCN Type: OSVDB ID: 34267 Linux Security Auditing Tool (LSAT) /tmp/lsat1.lsat Symlink Arbitrary File Overwrite Source: BID Type: UNKNOWN 23014 Source: CCN Type: BID-23014 Linux Security Auditing Tool Insecure Temporary File Creation Vulnerability Source: XF Type: UNKNOWN gentoo-lsat-symlink(33057) Source: XF Type: UNKNOWN gentoo-lsat-symlink(33057) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||