CVE-2007-6514
published 2007-12-21CVE-2007-6514: Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content…
PriorityP433medium4.3CVSS 2.0
AVNACMAuNCPINAN
EXPLOIT
EPSS
38.04%
98.4th percentile
Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat6.2MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
compiz-fusion: Possible locked desktop access by using Expo plugin mouse shortcuts
vendor_redhat·2008-07-09·CVSS 6.2
CVE-2008-6514 [MEDIUM] compiz-fusion: Possible locked desktop access by using Expo plugin mouse shortcuts
compiz-fusion: Possible locked desktop access by using Expo plugin mouse shortcuts
The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920.
Red Hat
When document is on smbfs, a trailing backslash at the end of file name bypasses content type match
vendor_redhat·2007-12-19·CVSS 4.3
CVE-2007-6514 [MEDIUM] When document is on smbfs, a trailing backslash at the end of file name bypasses content type match
When document is on smbfs, a trailing backslash at the end of file name bypasses content type match
Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.
Statement: Old versions of the Linux 2.4 kernel allowed the lookup of names containing backslashes over smbfs -- so there were multiple names which would reference any particular file, allowing the bypass of Apache controls such as AddType.
Not vulnerable. This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, or 5. This issue was corrected with a backported pa
GHSA
GHSA-49v2-h77h-w34h: Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed c
ghsa_unreviewed·2022-05-01
CVE-2007-6514 [MEDIUM] CWE-200 GHSA-49v2-h77h-w34h: Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed c
Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.
No detection rules found.
Bugzilla
CVE-2008-6514 compiz-fusion: Possible locked desktop access by using Expo plugin mouse shortcuts
bugzilla·2009-03-24·CVSS 6.2
CVE-2008-6514 [MEDIUM] CVE-2008-6514 compiz-fusion: Possible locked desktop access by using Expo plugin mouse shortcuts
CVE-2008-6514 compiz-fusion: Possible locked desktop access by using Expo plugin mouse shortcuts
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-6514 to
the following vulnerability:
The Expo plugin in Compiz Fusion 0.7.8 allows local users with
physical access to drag the screen saver aside and access the locked
desktop by using Expo mouse shortcuts, a related issue to
CVE-2007-3920.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6514
https://bugs.launchpad.net/ubuntu/+source/compiz-fusion-plugins-main/+bug/247088
http://bugzilla.gnome.org/show_bug.cgi?id=561567
http://www.securityfocus.com/bid/32712
http://secunia.com/advisories/33077
http://xforce.iss.net/xforce/xfdb/47172
Upstream patch:
http://gitweb.compiz-fusion.org/?p=fusion/plugins/expo;
Bugzilla
CVE-2007-6514 When document is on smbfs, a trailing backslash at the end of file name bypasses content type match
bugzilla·2007-12-21·CVSS 4.3
CVE-2007-6514 [MEDIUM] CVE-2007-6514 When document is on smbfs, a trailing backslash at the end of file name bypasses content type match
CVE-2007-6514 When document is on smbfs, a trailing backslash at the end of file name bypasses content type match
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6514 to the following vulnerability:
Apache HTTP Server, when running on Linux with a document root on a
Windows share mounted using smbfs, allows remote attackers to obtain
unprocessed content such as source files for .php programs via a
trailing "" (backslash), which is not handled by the intended AddType
directive.
References:
http://www.securityfocus.com/archive/1/archive/1/485316/100/0/threaded
http://www.securityfocus.com/bid/26939
http://xforce.iss.net/xforce/xfdb/39158
Discussion:
So it seems there is code in smbfs/dir.c to make sure that a EINTR is returned
if an attempt is made to open a file c
http://securityreason.com/securityalert/3479http://www.securityfocus.com/archive/1/485316/100/0/threadedhttp://www.securityfocus.com/bid/26939https://exchange.xforce.ibmcloud.com/vulnerabilities/39158http://securityreason.com/securityalert/3479http://www.securityfocus.com/archive/1/485316/100/0/threadedhttp://www.securityfocus.com/bid/26939https://exchange.xforce.ibmcloud.com/vulnerabilities/39158
2007-12-21
Published