Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2007-1716 | First vendor Publication | 2007-03-27 |
| Vendor | Cve | Last vendor Modification | 2011-03-07 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:L/AC:H/Au:M/C:P/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 3.4 | Attack Range | Local |
| Cvss Impact Score | 6.4 | Attack Complexity | High |
| Cvss Expoit Score | 1.2 | Authentification | Requires multiple instances |
| Calculate full CVSS 2.0 Vectors scores | |||
Security Protection
| Impacts | Provides unauthorized access : Allows partial confidentiality, integrity, and availability violation; Allows unauthorized disclosure of information; Allows disruption of service. |
Detail
pam_console does not properly restore ownership for certain console devices when there are multiple users logged into the console and one user logs out, which might allow local users to gain privileges. |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1716 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-708 | Incorrect Ownership Assignment |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:11483 | |||
| Oval ID: | oval:org.mitre.oval:def:11483 | ||
| Title: | pam_console does not properly restore ownership for certain console devices when there are multiple users logged into the console and one user logs out, which might allow local users to gain privileges. | ||
| Description: | pam_console does not properly restore ownership for certain console devices when there are multiple users logged into the console and one user logs out, which might allow local users to gain privileges. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2007-1716 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Os | 1 |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 37271 | pam_console Console Device Permission Restoration Weakness |
Internal Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2013-05-11 10:21:52 |
|

CVE-2007-1716
(Critical)
(Medium)
(Low)







