MEDIUM · 6.9

CVE-2007-1057

The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 1000 extracts and executes files with insecure permissions, which allows local use...

Vulnerability Description

The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 1000 extracts and executes files with insecure permissions, which allows local users to exploit a race condition to replace a world-writable file in /tmp/NetClient and cause another user to execute arbitrary code when attempting to execute this client, as demonstrated by replacing /tmp/NetClient/client.

CVSS Score

6.9

MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
NortelAlteon 2424 Application Switch23.2
NortelSsl Vpn Module 1000All versions
NortelVpn Gateway 3070All versions
NortelNet Direct Client<= 6.0.4

References

FAQ

What is CVE-2007-1057?

CVE-2007-1057 is a vulnerability with a CVSS score of 6.9 (MEDIUM). The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 1000 extracts and executes files with insecure permissions, which allows local use...

How severe is CVE-2007-1057?

CVE-2007-1057 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-1057?

Check the references section above for vendor advisories and patch information. Affected products include: Nortel Alteon 2424 Application Switch, Nortel Ssl Vpn Module 1000, Nortel Vpn Gateway 3070, Nortel Net Direct Client.