10

CVE-2011-2921

Exploit
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ktsuss ProjectKtsuss Version <= 1.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 82.83% 0.996
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-273 Improper Check for Dropped Privileges

The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.

http://packetstormsecurity.com/files/154307/ktsuss-Suid-Privilege-Escalation.html
Third Party Advisory
Exploit
VDB Entry
https://access.redhat.com/security/cve/cve-2011-2921
Third Party Advisory
Broken Link
https://security-tracker.debian.org/tracker/CVE-2011-2921
Third Party Advisory