PT-2005-5593 · Debian+1 · Libsensors3+5

Javier Fernández-Sanguino Peña

·

Publicado

1970-01-01

·

Atualizado

2018-10-03

·

CVE-2005-2672

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions lm-sensors versions prior to 2.9.1 libsensors3 (affected versions not specified) libsensors-dev (affected versions not specified) lm-sensors-2.4.27-2-386 (affected versions not specified) lm-sensors-2.4.27-2-586tsc (affected versions not specified) lm-sensors-2.4.27-2-686 (affected versions not specified) lm-sensors-2.4.27-2-686-smp (affected versions not specified) lm-sensors-2.4.27-2-k6 (affected versions not specified) lm-sensors-2.4.27-2-k7 (affected versions not specified) lm-sensors-2.4.27-2-k7-smp (affected versions not specified) kernel-patch-2.4-lm-sensors (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the lm-sensors package of the Debian GNU/Linux operating system, which can lead to the compromise of protected information. These vulnerabilities can be exploited by a local attacker. Specifically, the pwmconfig in LM sensors before version 2.9.1 creates temporary files insecurely, allowing local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary file.
Recommendations For lm-sensors versions prior to 2.9.1, update to version 2.9.1 or later to resolve the issue. For libsensors3, libsensors-dev, lm-sensors-2.4.27-2-386, lm-sensors-2.4.27-2-586tsc, lm-sensors-2.4.27-2-686, lm-sensors-2.4.27-2-686-smp, lm-sensors-2.4.27-2-k6, lm-sensors-2.4.27-2-k7, lm-sensors-2.4.27-2-k7-smp, and kernel-patch-2.4-lm-sensors, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03141
BDU:2015-03142
BDU:2015-03143
BDU:2015-03144
BDU:2015-03145
BDU:2015-03146
BDU:2015-03147
BDU:2015-03148
BDU:2015-03149
BDU:2015-03150
BDU:2015-03151
BDU:2015-03152
CVE-2005-2672
DSA-814-1
DTSA-17-1
RHSA-2005:825
RHSA-2005_825

Produtos afetados

Debian
Red Hat
Kernel-Patch-2.4-Lm-Sensors
Libsensors-Dev
Libsensors3
Lm-Sensors