Vulnerability Name: | CVE-2005-4279 (CCN-24601) | ||||||||
Assigned: | 2005-11-02 | ||||||||
Published: | 2005-11-02 | ||||||||
Updated: | 2011-03-08 | ||||||||
Summary: | Untrusted search path vulnerability in Qt-UnixODBC before 3.3.4-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-3580 Source: MITRE Type: CNA CVE-2005-3581 Source: MITRE Type: CNA CVE-2005-3582 Source: MITRE Type: CNA CVE-2005-4278 Source: MITRE Type: CNA CVE-2005-4279 Source: MITRE Type: CNA CVE-2005-4280 Source: MITRE Type: CNA CVE-2005-4442 Source: CCN Type: QDBM Web site QDBM: Quick Database Manager Source: SECUNIA Type: Vendor Advisory 17232 Source: CCN Type: SA55314 Oracle Solaris Perl Multiple Vulnerabilities Source: CCN Type: GLSA-200510-14 Perl, Qt-UnixODBC, CMake: RUNPATH issues Source: GENTOO Type: Patch GLSA-200510-14 Source: CCN Type: GLSA-200511-02 QDBM, ImageMagick, GDAL: RUNPATH issues Source: CCN Type: GLSA-200512-07 OpenLDAP, Gauche: RUNPATH issues Source: CCN Type: ImageMagick Web site ImageMagick: Convert, Edit, and Compose Images Source: OSVDB Type: UNKNOWN 20087 Source: CCN Type: OSVDB ID: 20086 Perl RUNPATH Variable Local Privilege Escalation Source: CCN Type: OSVDB ID: 20087 Qt-UnixODBC RUNPATH Variable Local Privilege Escalation Source: CCN Type: OSVDB ID: 20088 CMake RUNPATH Variable Local Privilege Escalation Source: CCN Type: OSVDB ID: 20527 QDBM RUNPATH Variable Local Privilege Escalation Source: CCN Type: OSVDB ID: 20528 ImageMagick RUNPATH Variable Local Privilege Escalation Source: CCN Type: OSVDB ID: 20529 GDAL RUNPATH Variable Local Privilege Escalation Source: BID Type: Patch 15120 Source: CCN Type: BID-15120 Gentoo Linux Multiple Packages Insecure RUNPATH Vulnerability Source: VUPEN Type: UNKNOWN ADV-2005-2119 Source: XF Type: UNKNOWN qdbm-portage-gain-privileges(24601) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |