cbcvebase.
CVE-2007-1507
published 2007-03-20

CVE-2007-1507: The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might allow attackers to…

PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.52%
83.0th percentile
The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might allow attackers to gain privileges by spoofing a response to an AFS cache manager FetchStatus request, and setting setuid and root ownership for files in the cache.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianopenafs< openafs 1.4.2-6 (bookworm)openafs 1.4.2-6 (bookworm)
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs
openafsopenafs>= 0 < 1.4.2-61.4.2-6
openafsopenafs>= 0 < 1.4.2-61.4.2-6
openafsopenafs>= 0 < 1.4.2-61.4.2-6

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.