2.1

CVE-2011-3196

The setup script in Domain Technologie Control (DTC) before 0.34.1 uses world-readable permissions for /etc/apache2/apache2.conf, which allows local users to obtain the dtcdaemons MySQL password by reading the file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GplhostDomain Technologie Control Version <= 0.32.11
GplhostDomain Technologie Control Version0.28.10
GplhostDomain Technologie Control Version0.29.10
GplhostDomain Technologie Control Version0.29.14
GplhostDomain Technologie Control Version0.29.15
GplhostDomain Technologie Control Version0.29.16
GplhostDomain Technologie Control Version0.29.17
GplhostDomain Technologie Control Version0.30.10
GplhostDomain Technologie Control Version0.30.18
GplhostDomain Technologie Control Version0.30.20
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.256
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://git.gplhost.com/gitweb/?p=dtc.git%3Ba=blob%3Bf=debian/changelog%3Bhb=3eb6ef5cea6c571aae5e49e1930de778eca280c3
http://www.debian.org/security/2011/dsa-2365
http://www.openwall.com/lists/oss-security/2011/08/13/1
http://www.openwall.com/lists/oss-security/2011/08/24/10
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=637485