CVE-2007-0472
EPSS 0.34%
描述
Multiple race conditions in Smb4K before 0.8.0 allow local users to (1) modify arbitrary files via unspecified manipulations of Smb4K's lock file, which is not properly handled by the remove_lock_file function in core/smb4kfileio.cpp, and (2) add lines to the sudoers file via a symlink attack on temporary files, which isn't properly handled by the writeFile function in core/smb4kfileio.cpp.
如何修補 CVE-2007-0472
要修補 CVE-2007-0472,請將受影響套件升級到下列已修補版本。
- Debian/smb4k—升級至 0.8.0-1 或更新版本
CVE-2007-0472 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 0.8.0-1