The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.
References
Configurations
History
21 Nov 2024, 00:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/27366 - | |
References | () http://security.gentoo.org/glsa/glsa-200710-25.xml - |
Information
Published : 2007-10-30 19:46
Updated : 2024-11-21 00:38
NVD link : CVE-2007-5714
Mitre link : CVE-2007-5714
CVE.ORG link : CVE-2007-5714
JSON object : View
Products Affected
gentoo
- mldonkey_ebuild
CWE
CWE-287
Improper Authentication