Smb4K: Multiple vulnerabilities Multiple vulnerabilities have been identified in Smb4K. smb4k 2007-03-09 2007-03-09 156152 local 0.6.10a 0.6.10a

Smb4K is a SMB/CIFS (Windows) share browser for KDE.

Kees Cook of the Ubuntu Security Team has identified multiple vulnerabilities in Smb4K.

A local attacker could gain unauthorized access to arbitrary files via numerous attack vectors. In some cases to obtain this unauthorized access, an attacker would have to be a member of the sudoers list.

There is no known workaround at this time.

All Smb4K users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/smb4k-0.6.10a"
CVE-2007-0472 CVE-2007-0473 CVE-2007-0474 CVE-2007-0475 falco falco shellsage