7.2

CVE-2009-0667

Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ocsinventory-ngOcs Inventory Ng Version1.0 Updatebeta
Ocsinventory-ngOcs Inventory Ng Version1.0 Updaterc1
Ocsinventory-ngOcs Inventory Ng Version1.0 Updaterc2
Ocsinventory-ngOcs Inventory Ng Version1.0 Updaterc3
Ocsinventory-ngOcs Inventory Ng Version1.0 Updaterc3-1
Ocsinventory-ngOcsinventory-agent Version <= 0.0.9.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.29
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506416
Patch
http://nana.rulezlan.org/~goneri/ocsinventory-agent/Ocsinventory-Agent-0.0.9.3.tar.gz
Patch
http://osvdb.org/55718
http://secunia.com/advisories/35727
http://secunia.com/advisories/35768
http://security.debian.org/pool/updates/main/o/ocsinventory-agent/ocsinventory-agent_0.0.9.2repack1-4lenny1.diff.gz
Patch
http://www.debian.org/security/2009/dsa-1828
Patch
http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt01articleid=144
http://www.securityfocus.com/bid/35593
Patch
http://www.vupen.com/english/advisories/2009/1809
Patch
Vendor Advisory