Multiple stack-based buffer overflows in utilities/smb4k_*.cpp in Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to gain privileges via unspecified vectors related to the args variable and unspecified other variables, in conjunction with the sudo configuration.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade smb4k | Jul 30, 2024 | Feb 3, 2007 |
| Gentoo Linux | — | Upgrade net-misc/smb4k. | Oct 30, 2017 | Feb 3, 2007 |
| Suse | — | Upgrade suse-releaseUpgrade smb4k | Dec 12, 2013 | Feb 3, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub