Vulnerability Description
The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gentoo | Linux | All versions |
References
- http://bugs.gentoo.org/show_bug.cgi?id=159542
- http://osvdb.org/34267
- http://secunia.com/advisories/24526Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200703-20.xml
- http://www.securityfocus.com/bid/23014
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33057
- http://bugs.gentoo.org/show_bug.cgi?id=159542
- http://osvdb.org/34267
- http://secunia.com/advisories/24526Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200703-20.xml
- http://www.securityfocus.com/bid/23014
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33057
FAQ
What is CVE-2007-1500?
CVE-2007-1500 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat.
How severe is CVE-2007-1500?
CVE-2007-1500 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-1500?
Check the references section above for vendor advisories and patch information. Affected products include: Gentoo Linux.