7.2

CVE-2004-1452

Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gentoo ≫ Linux Version 0.5
Gentoo ≫ Linux Version 0.7
Gentoo ≫ Linux Version 1.1a
Gentoo ≫ Linux Version 1.2
Gentoo ≫ Linux Version 1.4
Gentoo ≫ Linux Version 1.4 Update rc1
Gentoo ≫ Linux Version 1.4 Update rc2
Gentoo ≫ Linux Version 1.4 Update rc3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.35
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/12296/
Patch
http://www.gentoo.org/security/en/glsa/glsa-200408-15.xml
Patch
http://www.securityfocus.com/bid/10951
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/16993