Vulnerability Name: | CVE-2009-0854 (CCN-49216) | ||||||||
Assigned: | 2009-03-10 | ||||||||
Published: | 2009-03-10 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | Untrusted search path vulnerability in dash 0.5.4, when used as a login shell, allows local users to execute arbitrary code via a Trojan horse .profile file in the current working directory. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C) 5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.1 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-78 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-0854 Source: CCN Type: DASH Web page DASH Source: SECUNIA Type: UNKNOWN 34205 Source: CCN Type: OSVDB ID: 52999 dash login shell .profile Search Path Subversion Arbitrary Code Execution Source: BID Type: UNKNOWN 34092 Source: CCN Type: BID-34092 DASH '.profile' Local Privilege Escalation Vulnerability Source: CCN Type: USN-732-1 dash vulnerability Source: UBUNTU Type: UNKNOWN USN-732-1 Source: XF Type: UNKNOWN dash-profile-code-execution(49216) Source: XF Type: UNKNOWN dash-profile-code-execution(49216) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |