CVE-2007-5686

ADVISORY - debian

Summary

initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts. NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.


  • shadow (unimportant) See #290803, on Debian LOG_UNKFAIL_ENAB in login.defs is set to no so unknown usernames are not recorded on login failures
EPSS Score: 0.00245 (0.477)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Permissions, Privileges, and Access Controls


Debian

CREATED

UPDATED

ADVISORY IDCVE-2007-5686
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/shadowdebdebian12>=1:4.13+dfsg1-1+deb12u1Not yet available
debian/shadowdebdebianunstable>=1:4.17.4-2Not yet available
debian/shadowdebdebian11>=1:4.8.1-1Not yet available
debian/shadowdebdebian13>=1:4.17.4-2Not yet available

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

ADVISORY IDCVE-2007-5686
EXPLOITABILITY SCORE

3.9

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

4.9medium