9.9

CVE-2016-6902

lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lshell ProjectLshell Version0.9.16
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.08% 0.912
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.9 3.1 6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.openwall.com/lists/oss-security/2016/08/22/17
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/92591
Third Party Advisory
VDB Entry
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=834949
Patch
Third Party Advisory
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1369345
Patch
Issue Tracking
https://github.com/ghantoos/lshell/commit/a686f71732a3d0f16df52ef46ab8a49ee0083c68
Patch
Third Party Advisory
Issue Tracking
https://github.com/ghantoos/lshell/issues/147
Patch
Third Party Advisory
Issue Tracking