Vulnerability Name:

CVE-2007-5200 (CCN-37207)

Assigned:2007-10-12
Published:2007-10-12
Updated:2018-10-30
Summary:hugin, as used on various operating systems including SUSE openSUSE 10.2 and 10.3, allows local users to overwrite arbitrary files via a symlink attack on the hugin_debug_optim_results.txt temporary file.
CVSS v3 Severity:5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:3.3 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P)
2.9 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
3.3 Low (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P)
2.9 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-59
Vulnerability Consequences:File Manipulation
References:Source: MITRE
Type: CNA
CVE-2007-5200

Source: OSVDB
Type: UNKNOWN
42224

Source: SECUNIA
Type: Vendor Advisory
27229

Source: CCN
Type: SA27623
Hugin "hugin_debug_optim_results.txt" Insecure Temporary File

Source: SECUNIA
Type: Vendor Advisory
27623

Source: SECUNIA
Type: Vendor Advisory
27653

Source: SECUNIA
Type: Vendor Advisory
27952

Source: GENTOO
Type: UNKNOWN
GLSA-200712-01

Source: CCN
Type: GLSA-200712-01
Hugin: Insecure temporary file creation

Source: SUSE
Type: UNKNOWN
SUSE-SR:2007:020

Source: CCN
Type: OSVDB ID: 42224
Hugin hugin_debug_optim_results.txt Symlink Arbitrary File Overwrite

Source: BID
Type: UNKNOWN
26730

Source: CCN
Type: BID-26730
hugin Insecure Temporary File Creation Vulnerability

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=332401

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=362851

Source: XF
Type: UNKNOWN
suse-hugin-tmp-symlink(37207)

Source: FEDORA
Type: UNKNOWN
FEDORA-2007-2989

Source: SUSE
Type: SUSE-SR:2007:020
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/o:opensuse:opensuse:10.2:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:10.3:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:opensuse:opensuse:10.3:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20075200
    V
    CVE-2007-5200
    2022-06-30
    oval:org.opensuse.security:def:112413
    P
    hugin-2020.0.0-3.3 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:105920
    P
    Security update for net-snmp (Important)
    2022-01-11
    BACK
    opensuse opensuse 10.2
    opensuse opensuse 10.3
    novell opensuse 10.3
    gentoo linux *