Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-5936 | First vendor Publication | 2007-11-13 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:P/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 3.6 | Attack Range | Local |
Cvss Impact Score | 4.9 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain temporary files before they are processed by dviljk, which can then be read or modified in place. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5936 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-264 | Permissions, Privileges, and Access Controls |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2009-04-09 | Name : Mandriva Update for tetex MDKSA-2007:230 (tetex) File : nvt/gb_mandriva_MDKSA_2007_230.nasl |
2009-03-23 | Name : Ubuntu Update for tetex-bin, texlive-bin vulnerabilities USN-554-1 File : nvt/gb_ubuntu_USN_554_1.nasl |
2009-02-27 | Name : Fedora Update for tetex FEDORA-2007-3308 File : nvt/gb_fedora_2007_3308_tetex_fc8.nasl |
2009-02-27 | Name : Fedora Update for tetex FEDORA-2007-3390 File : nvt/gb_fedora_2007_3390_tetex_fc7.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200711-26 (tetex) File : nvt/glsa_200711_26.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200711-34 (cstetex) File : nvt/glsa_200711_34.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200805-13 (ptex) File : nvt/glsa_200805_13.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
42238 | teTeX dvips dviljk Temp File Race Condition Arbitrary File Modification |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2008-05-13 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200805-13.nasl - Type : ACT_GATHER_INFO |
2008-05-09 | Name : The remote openSUSE host is missing a security update. File : suse_texlive-bin-5221.nasl - Type : ACT_GATHER_INFO |
2008-01-08 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_te_ams-4818.nasl - Type : ACT_GATHER_INFO |
2008-01-08 | Name : The remote openSUSE host is missing a security update. File : suse_te_ams-4819.nasl - Type : ACT_GATHER_INFO |
2007-12-07 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-554-1.nasl - Type : ACT_GATHER_INFO |
2007-11-26 | Name : The remote Fedora host is missing a security update. File : fedora_2007-3308.nasl - Type : ACT_GATHER_INFO |
2007-11-26 | Name : The remote Fedora host is missing a security update. File : fedora_2007-3390.nasl - Type : ACT_GATHER_INFO |
2007-11-26 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200711-34.nasl - Type : ACT_GATHER_INFO |
2007-11-26 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2007-230.nasl - Type : ACT_GATHER_INFO |
2007-11-20 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200711-26.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:15:49 |
|
2024-11-28 12:14:00 |
|
2021-05-04 12:06:39 |
|
2021-04-22 01:07:10 |
|
2020-05-23 00:20:45 |
|
2018-10-16 00:19:20 |
|
2018-10-04 00:19:31 |
|
2016-06-28 17:03:16 |
|
2016-04-26 16:48:09 |
|
2014-02-17 10:42:34 |
|
2013-05-11 10:41:57 |
|