CVE-2007-5686

SOURCE - nist

Summary

initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts. NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.

EPSS Score: 0.00127 (0.473)

Common Weakness Enumeration (CWE)

SOURCE - nist

Permissions, Privileges, and Access Controls


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/shadowdebdebian12>=1:4.13+dfsg1-1Not yet available
debian/shadowdebdebian10>=1:4.5-1.1Not yet available
debian/shadowdebdebianunstable>=1:4.13+dfsg1-4Not yet available
debian/shadowdebdebian11>=1:4.8.1-1Not yet available
debian/shadowdebdebian13>=1:4.13+dfsg1-4Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

4.9medium