Vulnerability Description
smb4k 0.4 and other versions before 0.6.3 allows local users to read sensitive files via a symlink attack on the (1) smb4k.tmp or (2) sudoers temporary files.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smb4K | Smb4K | 0.4 |
References
- http://secunia.com/advisories/16724
- http://secunia.com/advisories/17636
- http://smb4k.berlios.de/Patch
- http://www.gentoo.org/security/en/glsa/glsa-200511-15.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:157PatchVendor Advisory
- http://www.securityfocus.com/bid/14756Patch
- http://secunia.com/advisories/16724
- http://secunia.com/advisories/17636
- http://smb4k.berlios.de/Patch
- http://www.gentoo.org/security/en/glsa/glsa-200511-15.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:157PatchVendor Advisory
- http://www.securityfocus.com/bid/14756Patch
FAQ
What is CVE-2005-2851?
CVE-2005-2851 is a vulnerability with a CVSS score of 2.1 (LOW). smb4k 0.4 and other versions before 0.6.3 allows local users to read sensitive files via a symlink attack on the (1) smb4k.tmp or (2) sudoers temporary files.
How severe is CVE-2005-2851?
CVE-2005-2851 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2851?
Check the references section above for vendor advisories and patch information. Affected products include: Smb4K Smb4K.