Vulnerabilities > CVE-2007-3531 - Unspecified vulnerability in Gentoo Nvclock 0.7
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN gentoo
nessus
Summary
The set_default_speeds function in backend/backend.c in NVidia NVClock before 0.8b2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvclock temporary file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 6 | |
Application | 2 |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200707-08.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200707-08 (NVClock: Insecure file usage) Tavis Ormandy of the Gentoo Linux Security Team discovered that NVClock makes usage of an insecure temporary file in the /tmp directory. Impact : A local attacker could create a specially crafted temporary file in /tmp to execute arbitrary code with the privileges of the user running NVCLock. Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25790 |
published | 2007-07-27 |
reporter | This script is Copyright (C) 2007-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25790 |
title | GLSA-200707-08 : NVClock: Insecure file usage |
code |
|
References
- http://bugs.gentoo.org/show_bug.cgi?id=184071
- http://bugs.gentoo.org/show_bug.cgi?id=184071
- http://osvdb.org/38573
- http://osvdb.org/38573
- http://secunia.com/advisories/26200
- http://secunia.com/advisories/26200
- http://secunia.com/advisories/26208
- http://secunia.com/advisories/26208
- http://security.gentoo.org/glsa/glsa-200707-08.xml
- http://security.gentoo.org/glsa/glsa-200707-08.xml
- http://www.securityfocus.com/bid/25052
- http://www.securityfocus.com/bid/25052
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35584
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35584