7.2
CVE-2005-0070
- EPSS 0.37%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:10:26
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Synaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before processing configuration and mixer files, which allows local users to read arbitrary files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Synaesthesia ≫ Synaesthesia Version <= 2.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.285 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
http://secunia.com/advisories/14300
http://securitytracker.com/id?1013206
http://www.debian.org/security/2005/dsa-681
http://www.securityfocus.com/bid/12546