7.2
CVSSv2

CVE-2007-2838

Published: 03/07/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The populate_conns function in src/populate_conns.c in GSAMBAD 0.1.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gsambadtmp temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

gsambad gsambad 0.1.4

Vendor Advisories

Steve Kemp from the Debian Security Audit project discovered that gsambad, a GTK+ configuration tool for samba, uses temporary files in an unsafe manner which may be exploited to truncate arbitrary files from the local system For the stable distribution (etch) this problem has been fixed in version 014-2etch1 For the unstable distribution (sid) ...