9.9
CVE-2016-6903
- EPSS 4.94%
- Veröffentlicht 24.04.2017 19:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Quelle security@debian.org
- CVE-Watchlists
- Unerledigt
lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lshell Project ≫ Lshell Version0.9.16
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.94% | 0.91 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.9 | 3.1 | 6 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
| nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
http://www.openwall.com/lists/oss-security/2016/08/22/17
http://www.securityfocus.com/bid/92591
https://bugzilla.redhat.com/show_bug.cgi?id=1369345
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=834946
https://github.com/ghantoos/lshell/commit/e72dfcd1f258193f9aaea3591ecbdaed207661a0
https://github.com/ghantoos/lshell/issues/149
https://github.com/ghantoos/lshell/pull/153/commits/a686f71732a3d0f16df52ef46ab8a49ee0083c68