Vulnerability Name: | CVE-2005-3629 (CCN-25374) | ||||||||||||||||
Assigned: | 2005-03-07 | ||||||||||||||||
Published: | 2005-03-07 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors. | ||||||||||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||
References: | Source: SGI Type: UNKNOWN 20060401-01-U Source: CCN Type: SGI Security Advisory 20060401-01-U SGI Advanced Linux Environment 3 Security Update #56 Source: MITRE Type: CNA CVE-2005-3629 Source: CCN Type: RHSA-2006-0015 initscripts security update Source: CCN Type: RHSA-2006-0016 initscripts security update Source: SECUNIA Type: Patch, Vendor Advisory 19162 Source: SECUNIA Type: UNKNOWN 19532 Source: CCN Type: SECTRACK ID: 1015732 Red Hat initscripts Environment Variable Processing May Let Local Users Gain Elevated Privileges Source: SECTRACK Type: Patch, Vendor Advisory 1015732 Source: CCN Type: ASA-2006-170 initscripts security update (RHSA-2006-0016) Source: REDHAT Type: UNKNOWN RHSA-2006:0015 Source: REDHAT Type: Patch, Vendor Advisory RHSA-2006:0016 Source: BID Type: UNKNOWN 17038 Source: CCN Type: BID-17038 Red Hat Initscripts Local Privilege Escalation Vulnerability Source: XF Type: UNKNOWN initscripts-service-privilege-escalation(25374) Source: XF Type: UNKNOWN initscripts-service-gain-privileges(25374) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11198 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |