Vulnerability Name: | CCN-112327 | ||||||
Published: | 2016-04-18 | ||||||
Updated: | 2016-04-18 | ||||||
Summary: | NetBSD could allow a local attacker to gain elevated privileges on the system, caused by the failure to properly drop super user privileges when calling external applications by the calendar(1) utility. An attacker could exploit this vulnerability to read arbitrary files and gain elevated privileges on the system. | ||||||
CVSS v3 Severity: | 8.4 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||
CVSS v2 Severity: | 7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||
Vulnerability Consequences: | Gain Privileges | ||||||
References: | Source: CCN Type: NetBSD Security Advisory 2016-003 Privilege escalation in calendar(1) Source: XF Type: UNKNOWN netbsd-calendar-priv-esc(112327) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |