4.4

CVE-2014-0039

Exploit
Untrusted search path vulnerability in fwsnort before 1.6.4, when not running as root, allows local users to execute arbitrary code via a Trojan horse fwsnort.conf in the current working directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CipherdyneFwsnort Version <= 1.6.4
CipherdyneFwsnort Version0.5
CipherdyneFwsnort Version0.6
CipherdyneFwsnort Version0.6.1
CipherdyneFwsnort Version0.6.2
CipherdyneFwsnort Version0.6.3
CipherdyneFwsnort Version0.6.4
CipherdyneFwsnort Version0.6.5
CipherdyneFwsnort Version0.7.0
CipherdyneFwsnort Version0.8.0
CipherdyneFwsnort Version0.8.1
CipherdyneFwsnort Version0.8.2
CipherdyneFwsnort Version0.9.0
CipherdyneFwsnort Version1.0
CipherdyneFwsnort Version1.0.1
CipherdyneFwsnort Version1.0.2
CipherdyneFwsnort Version1.0.3
CipherdyneFwsnort Version1.0.4
CipherdyneFwsnort Version1.0.5
CipherdyneFwsnort Version1.0.6
CipherdyneFwsnort Version1.5
CipherdyneFwsnort Version1.6
CipherdyneFwsnort Version1.6.1
CipherdyneFwsnort Version1.6.2
CipherdyneFwsnort Version1.6.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.44
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128188.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128205.html
http://osvdb.org/102822
http://seclists.org/oss-sec/2014/q1/221
http://www.securityfocus.com/bid/65341
https://github.com/mrash/fwsnort/blob/master/ChangeLog
https://github.com/mrash/fwsnort/commit/fa977453120cc48e1654f373311f9cac468d3348
Patch
Exploit