3.6
CVSSv2

CVE-2007-2837

Published: 03/07/2007 Updated: 29/07/2017
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

The (1) getRule and (2) getChains functions in server/rules.cpp in fireflierd (fireflier-server) in FireFlier 1.1.6 allow local users to overwrite arbitrary files via a symlink attack on the /tmp/fireflier.rules temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

fireflier fireflier 1.1.6

Vendor Advisories

Steve Kemp from the Debian Security Audit project discovered that fireflier-server, an interactive firewall rule creation tool, uses temporary files in an unsafe manner which may be exploited to remove arbitrary files from the local system For the old stable distribution (sarge) this problem has been fixed in version 115-1sarge1 For the stable ...