« Volver al listado

CVE-2007-1507

Estado: ModificadaAlta (7.5)—

The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might allow attackers to gain privileges by spoofing a response to an AFS cache manager FetchStatus request, and setting setuid and root ownership for files in the cache.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-1507",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-03-20T10:19:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/24582",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/24599",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/24607",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/24720",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-200704-03.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.debian.org/security/2007/dsa-1271",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:066",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openafs.org/pipermail/openafs-announce/2007/000185.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openafs.org/pipermail/openafs-announce/2007/000186.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openafs.org/pipermail/openafs-announce/2007/000187.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/23060",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1017807",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1033",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33180",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/24582",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/24599",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/24607",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/24720",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-200704-03.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2007/dsa-1271",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:066",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openafs.org/pipermail/openafs-announce/2007/000185.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openafs.org/pipermail/openafs-announce/2007/000186.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openafs.org/pipermail/openafs-announce/2007/000187.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/23060",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1017807",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1033",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33180",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-16"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might allow attackers to gain privileges by spoofing a response to an AFS cache manager FetchStatus request, and setting setuid and root ownership for files in the cache."
    },
    {
      "lang": "es",
      "value": "La configuración predeterminada en OpenAFS versiones 1.4.x anteriores a 1.4.4 y versiones 1.5.x anteriores a 1.5.17, admite programas setuid dentro de la celda local, lo que podría permitir a atacantes alcanzar privilegios suplantando una respuesta a una petición FetchStatus del administrador de caché AFS y establecer la propiedad de setuid y root para archivos en la memoria caché."
    }
  ],
  "lastModified": "2026-06-16T22:37:43.463",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0F37635-C186-4D06-A79C-2A7AB0CFBAD9"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89E75B7E-B38C-48AD-B04F-BD705AFF2907"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F38E889-0CC0-49E1-9B6C-90D4176C06C6"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB1364B7-D564-4385-B7D7-67184E474712"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.4.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA3D7891-0B48-4C5D-B74B-6810FB4696F4"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "382FC10C-4C00-438C-89AD-7D68C5D27873"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77564116-CF64-4D8D-BA54-A8E9BCA95EDD"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "237C1DCE-D907-4552-9EC0-05209A64D0E9"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC82946D-1211-4382-8D48-5F5B55E4DF35"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06DA2004-0A16-4D10-82FF-6CB2AC578331"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E4D5363-E9B9-4B60-9B22-F6FDF3DCA6DD"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1538B29-860C-4FF4-A807-46509FBFEC2B"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F81B547-2DE0-4707-94B6-1878E820883C"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD9FD959-477E-4DF1-A115-D59D21EB0568"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25AA0ACE-A8C6-4234-8EE2-F52438B6F472"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1E141BE-9ECF-4275-BFBD-E3DBF7D86A39"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C85F39C-C8D3-4493-8432-5EE3FB231BE9"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C158198E-8D22-41A8-8C24-8ABBE3354F33"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.14:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F377FB25-17B5-48A8-BC3C-3E99649C429E"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.15:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA4033D1-2374-429D-8927-F51EDC24E96B"
            },
            {
              "criteria": "cpe:2.3:a:openafs:openafs:1.5.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39308049-0C20-4845-9803-529A85CB9682"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}