PT-2007-1050 · Jorg Schilling+2 · Cdrtools+5
Andrew D
·
Published
2007-03-27
·
Updated
2017-10-11
·
CVE-2007-1716
CVSS v2.0
3.4
Low
| Vector | AV:L/AC:H/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
pam-devel versions 0.75
pam versions 0.75
cdrtools versions 2.01.0.a32
cdrecord-devel versions 2.01.0.a32
cdrecord versions 2.01.0.a32
Description:
The issue affects the confidentiality, integrity, and availability of protected information in Red Hat Enterprise Linux. It can be exploited locally, potentially allowing local users to gain privileges. The exploitation might occur when there are multiple users logged into the console and one user logs out.
Recommendations:
For pam-devel version 0.75, update to a newer version that contains a fix for this issue.
For pam version 0.75, update to a newer version that contains a fix for this issue.
For cdrtools version 2.01.0.a32, update to a newer version that contains a fix for this issue.
For cdrecord-devel version 2.01.0.a32, update to a newer version that contains a fix for this issue.
For cdrecord version 2.01.0.a32, update to a newer version that contains a fix for this issue.
As a temporary workaround, consider restricting access to sensitive console devices to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Cdrecord
Cdrecord-Devel
Cdrtools
Pam
Pam-Devel