Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-1057
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-1057

Description:
The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 1000 extracts and executes files with insecure permissions, which allows local users to exploit a race condition to replace a world-writable file in /tmp/NetClient and cause another user to execute arbitrary code when attempting to execute this client, as demonstrated by replacing /tmp/NetClient/client.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/32597

ST
  1017678

SAID
  Secunia Advisory: SA24231

OSVDB
  33304

MISC
  http://spoofed.org/blog/archive/2007/02/nortel_vpn_unix_client_local_root_compromise.html

MILW0RM
  http://www.milw0rm.com/exploits/3356

CONFIRM
  http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=540071
  http://www116.nortelnetworks.com/pub/repository/CLARIFY/DOCUMENT/2007/08/021886-01.pdf

BID
  22632


Return to the previous page.