7.2

CVE-2006-0576

Untrusted search path vulnerability in opcontrol in OProfile 0.9.1 and earlier allows local users to execute arbitrary commands via a modified PATH that references malicious (1) which or (2) dirname programs.  NOTE: while opcontrol normally is not run setuid, a common configuration suggests accessing opcontrol using sudo.  In such a context, this is a vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Maynard JohnsonOprofile Version <= 0.9.1
Maynard JohnsonOprofile Version0.1
Maynard JohnsonOprofile Version0.2
Maynard JohnsonOprofile Version0.3
Maynard JohnsonOprofile Version0.4
Maynard JohnsonOprofile Version0.5
Maynard JohnsonOprofile Version0.5.1
Maynard JohnsonOprofile Version0.5.2
Maynard JohnsonOprofile Version0.5.3
Maynard JohnsonOprofile Version0.5.4
Maynard JohnsonOprofile Version0.6
Maynard JohnsonOprofile Version0.6.1
Maynard JohnsonOprofile Version0.7
Maynard JohnsonOprofile Version0.7.1
Maynard JohnsonOprofile Version0.8
Maynard JohnsonOprofile Version0.8.1
Maynard JohnsonOprofile Version0.8.2
Maynard JohnsonOprofile Version0.9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.191
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.