PT-2007-1038 · Debian · Debian-Goodies

Thomas De Grenier De Latour

·

Publicado

2007-09-10

·

Atualizado

2017-07-29

·

CVE-2007-3912

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: debian-goodies versions prior to 0.34
Description: The issue concerns multiple vulnerabilities in the debian-goodies package of the Debian GNU/Linux operating system. These vulnerabilities can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. Specifically, the checkrestart utility in debian-goodies is vulnerable to shell metacharacters in the name of the executable file for a running process, allowing local users to gain privileges.
Recommendations: For versions prior to 0.34, update to version 0.34 or later to resolve the issue. As a temporary workaround, consider restricting access to the checkrestart utility to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03318
CVE-2007-3912
DSA-1527-1

Produtos afetados

Debian-Goodies