Vulnerability Name: | CVE-2004-0395 (CCN-16273) | ||||||||
Assigned: | 2004-05-30 | ||||||||
Published: | 2004-05-30 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | The xatitv program in the gatos package does not properly drop root privileges when the configuration file does not exist, which allows local users to execute arbitrary commands via shell metacharacters in a system call. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2004-0395 Source: CCN Type: SourceForge.net SourceForge.net: Project Info - GATOS Source: DEBIAN Type: Patch, Vendor Advisory DSA-509 Source: DEBIAN Type: DSA-509 gatos -- privilege escalation Source: CCN Type: OSVDB ID: 6501 Debian GATOS xatitv Initialization Privilege Escalation Source: BID Type: Patch, Vendor Advisory 10437 Source: CCN Type: BID-10437 Gatos xatitv Missing Configuration File Privilege Escalation Vulnerability Source: XF Type: UNKNOWN gatos-xatitv-gain-privileges(16273) Source: XF Type: UNKNOWN gatos-xatitv-gain-privileges(16273) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |