9.9

CVE-2016-6903

lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lshell ProjectLshell Version0.9.16
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.94% 0.91
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.9 3.1 6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.openwall.com/lists/oss-security/2016/08/22/17
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/92591
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1369345
Patch
Issue Tracking
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=834946
Patch
Third Party Advisory
Issue Tracking
https://github.com/ghantoos/lshell/commit/e72dfcd1f258193f9aaea3591ecbdaed207661a0
Patch
Third Party Advisory
Issue Tracking
https://github.com/ghantoos/lshell/issues/149
Patch
Third Party Advisory
Issue Tracking
https://github.com/ghantoos/lshell/pull/153/commits/a686f71732a3d0f16df52ef46ab8a49ee0083c68
Patch
Third Party Advisory
Issue Tracking