| Vulnerability Name: | CVE-2005-0503 (CCN-19397) | ||||||||
| Assigned: | 2005-02-21 | ||||||||
| Published: | 2005-02-21 | ||||||||
| Updated: | 2008-09-10 | ||||||||
| Summary: | uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges. | ||||||||
| CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: MITRE Type: CNA CVE-2005-0503 Source: CCN Type: Uim Mailing List, Sun Feb 20 05:13:52 PST 2005 Uim] uim 0.4.5.1 released Source: MLIST Type: Vendor Advisory [uim] 20050220 uim 0.4.5.1 released Source: CCN Type: SA13981 uim Environment Variable Trust Privilege Escalation Source: SECUNIA Type: Patch, Vendor Advisory 13981 Source: CCN Type: uim Web site FrontPage - A uim Wiki Source: CCN Type: GLSA-200502-31 uim: Privilege escalation vulnerability Source: MANDRAKE Type: UNKNOWN MDKSA-2005:046 Source: CCN Type: OSVDB ID: 14013 uim Environment Variable Local Privilege Escalation Source: BID Type: Patch, Vendor Advisory 12604 Source: CCN Type: BID-12604 UIM LibUIM Environment Variables Privilege Escalation Weakness Source: XF Type: UNKNOWN uim-environment-variable-gain-privilege(19397) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||