6.9
CVE-2009-2904
- EPSS 0.04%
- Published 01.10.2009 15:30:00
- Last modified 09.04.2025 00:30:58
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11, allows local users to gain privileges via hard links to setuid programs that use configuration files within the chroot directory, related to requirements for directory ownership.
Data is provided by the National Vulnerability Database (NVD)
Openbsd ≫ Openssh Version4.3
Fedoraproject ≫ Fedora Version11
Redhat ≫ Enterprise Linux Version5 Editionserver
Redhat ≫ Enterprise Linux Desktop Version5 Editionclient
Redhat ≫ Enterprise Linux Eus Version5
Redhat ≫ Enterprise Linux Version5 Editionserver
Redhat ≫ Enterprise Linux Desktop Version5 Editionclient
Redhat ≫ Enterprise Linux Eus Version5
Openbsd ≫ Openssh Version4.8
Fedoraproject ≫ Fedora Version11
Redhat ≫ Enterprise Linux Version5 Editionserver
Redhat ≫ Enterprise Linux Desktop Version5 Editionclient
Redhat ≫ Enterprise Linux Eus Version5
Redhat ≫ Enterprise Linux Version5 Editionserver
Redhat ≫ Enterprise Linux Desktop Version5 Editionclient
Redhat ≫ Enterprise Linux Eus Version5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.115 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|