4.6

CVE-2004-2610

Exploit
mntd_mount.c in mntd before 0.4.2 might allow local users to gain privileges via shell metacharacters in a remount option in the configuration file.  NOTE: It is not clear whether this is a vulnerability because there is not necessarily any common usage in which privilege boundaries are crossed.  Typical usage would restrict write access to the configuration file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Stefan BambachMntd Version0.3.4
Stefan BambachMntd Version0.3.5
Stefan BambachMntd Version0.4.0
Stefan BambachMntd Version0.4.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.351
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://prdownloads.sourceforge.net/mntd/mntd-0.4.2.tar.gz?download
Patch
http://securitytracker.com/id?1011088
Exploit
http://www.osvdb.org/9380
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/17149