CVE-2007-6131
published 2007-11-26CVE-2007-6131: buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) scan.pnm and (2) scan.jpg temporary files.
PriorityP47low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.41%
33.3th percentile
buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) scan.pnm and (2) scan.jpg temporary files.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | fedora_core | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-63hp-2j26-qmh4: buttonpressed
ghsa_unreviewed·2022-05-01
CVE-2007-6131 [LOW] GHSA-63hp-2j26-qmh4: buttonpressed
buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) scan.pnm and (2) scan.jpg temporary files.
Red Hat
scanbuttond: unsafe usage of temporary files in buttonpressed.sh
vendor_redhat·2007-11-14·CVSS 2.1
CVE-2007-6131 [LOW] scanbuttond: unsafe usage of temporary files in buttonpressed.sh
scanbuttond: unsafe usage of temporary files in buttonpressed.sh
buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) scan.pnm and (2) scan.jpg temporary files.
No detection rules found.
No public exploits indexed.
http://osvdb.org/42422http://secunia.com/advisories/27847http://securitytracker.com/id?1019007http://www.securityfocus.com/bid/26617http://www.vupen.com/english/advisories/2007/4024https://bugzilla.redhat.com/show_bug.cgi?id=383131http://osvdb.org/42422http://secunia.com/advisories/27847http://securitytracker.com/id?1019007http://www.securityfocus.com/bid/26617http://www.vupen.com/english/advisories/2007/4024https://bugzilla.redhat.com/show_bug.cgi?id=383131
2007-11-26
Published