smb4k 0.4 and other versions before 0.6.3 allows local users to read sensitive files via a symlink attack on the (1) smb4k.tmp or (2) sudoers temporary files.
Link | Tags |
---|---|
http://www.mandriva.com/security/advisories?name=MDKSA-2005:157 | patch vendor advisory |
http://secunia.com/advisories/16724 | third party advisory |
http://www.securityfocus.com/bid/14756 | vdb entry patch |
http://www.gentoo.org/security/en/glsa/glsa-200511-15.xml | vendor advisory |
http://smb4k.berlios.de/ | patch |
http://secunia.com/advisories/17636 | third party advisory |