3.3
CVSSv2

CVE-2007-5200

Published: 14/10/2007 Updated: 30/10/2018
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

hugin, as used on various operating systems including SUSE openSUSE 10.2 and 10.3, allows local users to overwrite arbitrary files via a symlink attack on the hugin_debug_optim_results.txt temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 10.3

opensuse opensuse 10.2

Vendor Advisories

Debian Bug report logs - #447344 CVE-2007-5200 insecure tmp file handling Package: hugin; Maintainer for hugin is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Source for hugin is src:hugin (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Sat, 20 Oct 2007 10:18:01 ...