GLSA-200703-09 : Smb4K: Multiple vulnerabilities

medium Nessus Plugin ID 24801

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-200703-09 (Smb4K: Multiple vulnerabilities)

Kees Cook of the Ubuntu Security Team has identified multiple vulnerabilities in Smb4K.
The writeFile() function of smb4k/core/smb4kfileio.cpp makes insecure usage of temporary files.
The writeFile() function also stores the contents of the sudoers file with incorrect permissions, allowing for the file's contents to be world-readable.
The createLockFile() and removeLockFile() functions improperly handle lock files, possibly allowing for a race condition in file handling.
The smb4k_kill utility distributed with Smb4K allows any user in the sudoers group to kill any process on the system.
Lastly, there is the potential for multiple stack overflows when any Smb4K utility is used with the sudo command.
Impact :

A local attacker could gain unauthorized access to arbitrary files via numerous attack vectors. In some cases to obtain this unauthorized access, an attacker would have to be a member of the sudoers list.
Workaround :

There is no known workaround at this time.

Solution

All Smb4K users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=net-misc/smb4k-0.6.10a'

See Also

https://security.gentoo.org/glsa/200703-09

Plugin Details

Severity: Medium

ID: 24801

File Name: gentoo_GLSA-200703-09.nasl

Version: 1.15

Type: local

Published: 3/12/2007

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.8

CVSS v2

Risk Factor: Medium

Base Score: 4.4

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:smb4k, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Patch Publication Date: 3/9/2007

Vulnerability Publication Date: 12/21/2006

Reference Information

CVE: CVE-2007-0472, CVE-2007-0473, CVE-2007-0474, CVE-2007-0475

GLSA: 200703-09