Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2012-2653 - CERT CVE
CVE-2012-2653
ID
CVE-2012-2653
Sažetak
arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.
Reference
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082553.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082565.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082569.html
http://www.debian.org/security/2012/dsa-2481
http://www.mandriva.com/security/advisories?name=MDVSA-2012:113
http://www.openwall.com/lists/oss-security/2012/05/24/12
http://www.openwall.com/lists/oss-security/2012/05/24/13
http://www.openwall.com/lists/oss-security/2012/05/24/14
http://www.openwall.com/lists/oss-security/2012/05/25/5
https://security.gentoo.org/glsa/201607-16
CVSS
Base:
10.0
Impact:
10.0
Exploitability:
10.0
Pristup
Vektor
Složenost
Autentikacija
NETWORK
LOW
NONE
Impact
Povjerljivost
Cjelovitost
Dostupnost
COMPLETE
COMPLETE
COMPLETE
CVSS vektor
AV:N/AC:L/Au:N/C:C/I:C/A:C
Zadnje važnije ažuriranje
28-11-2016 - 19:08
Objavljeno
12-07-2012 - 20:55