| Vulnerability Name: | CVE-2005-2657 (CCN-21851) | ||||||||
| Assigned: | 2005-08-16 | ||||||||
| Published: | 2005-08-16 | ||||||||
| Updated: | 2017-07-11 | ||||||||
| Summary: | Unknown vulnerability in common-lisp-controller 4.18 and earlier allows local users to gain privileges by compiling arbitrary code in the cache directory, which is executed by another user if the user has not run Common Lisp before. | ||||||||
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Other | ||||||||
| References: | Source: MITRE Type: CNA CVE-2005-2626 Source: MITRE Type: CNA CVE-2005-2657 Source: CCN Type: SA16447 Kismet Multiple Vulnerabilities Source: CCN Type: SA16822 common-lisp-controller Cache Directory Privilege Escalation Source: SECUNIA Type: Vendor Advisory 16822 Source: DEBIAN Type: Patch, Vendor Advisory DSA-811 Source: DEBIAN Type: DSA-788 kismet -- several vulnerabilities Source: DEBIAN Type: DSA-811 common-lisp-controller -- design error Source: CCN Type: GLSA-200508-10 Kismet: Multiple vulnerabilities Source: CCN Type: Kismet Web site Kismet Source: CCN Type: Kismet Change log Kismet Source: CCN Type: OSVDB ID: 18767 Kismet SSID Character Processing Issue Source: CCN Type: BID-14430 Kismet Multiple Remote Vulnerabilities Source: BID Type: Patch 14829 Source: CCN Type: BID-14829 Common-Lisp-Controller Cache Arbitrary Code Injection Vulnerability Source: XF Type: UNKNOWN kismet-ssid-unspecified(21851) Source: XF Type: UNKNOWN common-lisp-controller-cache-gain-priv(22275) Source: SUSE Type: SUSE-SR:2005:020 SUSE Security Summary Report | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| Vulnerability Name: | CVE-2005-2657 (CCN-22275) | ||||||||
| Assigned: | 2005-09-14 | ||||||||
| Published: | 2005-09-14 | ||||||||
| Updated: | 2005-09-14 | ||||||||
| Summary: | common-lisp-controller could allow a local attacker to gain elevated privileges. A local attacker could compile malicious code in the cache directory that would be executed when a victim uses common-lisp-controller for the first time. A local attacker could exploit this vulnerability to gain elevated privileges. | ||||||||
| CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: MITRE Type: CNA CVE-2005-2657 Source: CCN Type: SA16822 common-lisp-controller Cache Directory Privilege Escalation Source: CCN Type: common-lisp-controller Web site CLiki : common-lisp-controller Source: DEBIAN Type: DSA-811 common-lisp-controller -- design error Source: CCN Type: BID-14829 Common-Lisp-Controller Cache Arbitrary Code Injection Vulnerability Source: XF Type: UNKNOWN common-lisp-controller-cache-gain-priv(22275) | ||||||||
| Oval Definitions | |||||||||
| |||||||||
| BACK | |||||||||