CVE-2007-0476
Last modified
CVE-2007-0476 is a vulnerability of currently unknown severity. The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to overwrite arbitrary files via a symlink attack.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to overwrite arbitrary files via a symlink attack.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Gentoo | Linux | 2.1.30 | R9 |
| Gentoo | Linux | 2.2.28 | R7 |
| Gentoo | Linux | 2.3.30 | R2 |
References
- http://secunia.com/advisories/23881Vendor Advisory
- http://secunia.com/advisories/23881Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0476?
How severe is CVE-2007-0476?
How do I fix CVE-2007-0476?
Are you affected by CVE-2007-0476?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
