« Volver al listado

CVE-2007-5377

Estado: ModificadaMedia (6.9)—

Las funciones (1) tramp-make-temp-file y (2) tramp-make-tramp-temp-file en la extensión Tramp 2.1.10 para Emacs, y posiblemente versiones anteriores 2.1.x, permite a usuarios locales sobrescribir ficheros de su elección a través de ataques de enlaces simbólicos sobre archivos temporales.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-5377",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-10-12T00:17:00.000",
  "references": [
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=194713",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.gnu.org/archive/html/emacs-devel/2007-10/msg00132.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.gnu.org/archive/html/emacs-devel/2007-10/msg00158.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/41752",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/27244",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/27343",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200710-22.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/26072",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=194713",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.gnu.org/archive/html/emacs-devel/2007-10/msg00132.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.gnu.org/archive/html/emacs-devel/2007-10/msg00158.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/41752",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/27244",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/27343",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200710-22.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/26072",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-59"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The (1) tramp-make-temp-file and (2) tramp-make-tramp-temp-file functions in Tramp 2.1.10 extension for Emacs, and possibly earlier 2.1.x versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files."
    },
    {
      "lang": "es",
      "value": "Las funciones (1) tramp-make-temp-file y (2) tramp-make-tramp-temp-file en la extensión Tramp 2.1.10 para Emacs, y posiblemente versiones anteriores 2.1.x, permite a usuarios locales sobrescribir ficheros de su elección a través de ataques de enlaces simbólicos sobre archivos temporales."
    }
  ],
  "lastModified": "2026-06-16T22:45:59.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnu:tramp:2.1.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FC68054-61C2-4482-B95B-5EBB5D21C67D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "Not vulnerable.  Red Hat Enterprise Linux 2.1, 3, and 4 did not include the Tramp extension with Emacs.  The version of Tramp included with Emacs in Red Hat Enterprise Linux 5 was not vulnerable to this issue.\n",
      "lastModified": "2007-10-17T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}