6.2

CVE-2011-0532

The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Server 8.2.x) place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ 389 Directory Server Version 1.2.5 Update rc1
Fedoraproject ≫ 389 Directory Server Version 1.2.5 Update rc2
Fedoraproject ≫ 389 Directory Server Version 1.2.5 Update rc3
Fedoraproject ≫ 389 Directory Server Version 1.2.5 Update rc4
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update a2
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update a3
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update a4
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc1
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc2
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc3
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc6
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc7
Fedoraproject ≫ 389 Directory Server Version 1.2.6.1
Fedoraproject ≫ 389 Directory Server Version 1.2.7 Update alpha3
Fedoraproject ≫ 389 Directory Server Version 1.2.7.5
Fedoraproject ≫ 389 Directory Server Version 1.2.8 Update alpha1
Fedoraproject ≫ 389 Directory Server Version 1.2.8 Update alpha2
Redhat ≫ Directory Server Version 8.2
Redhat ≫ Directory Server Version 8.2.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.199
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.2 1.9 10
AV:L/AC:H/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.redhat.com/support/errata/RHSA-2011-0293.html
http://www.securityfocus.com/bid/46489
http://www.securitytracker.com/id?1025102
https://bugzilla.redhat.com/show_bug.cgi?id=672468
https://exchange.xforce.ibmcloud.com/vulnerabilities/65637