Vulnerability Name: | CVE-2011-0468 (CCN-66245) | ||||||||
Assigned: | 2011-03-22 | ||||||||
Published: | 2011-03-22 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | The aaa_base package before 11.3-8.9.1 in SUSE openSUSE 11.3, and before 11.4-54.62.1 in openSUSE 11.4, allows local users to gain privileges via shell metacharacters in a filename, related to tab expansion. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C) 5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-0468 Source: SUSE Type: UNKNOWN SUSE-SR:2011:005 Source: MLIST Type: Vendor Advisory [opensuse-updates] 20110322 openSUSE-SU-2011:0207-1 (moderate): aaa_base security update Source: CCN Type: SA43825 SUSE aaa_base Tab Expansion Filename Handling Privilege Escalation Source: SECUNIA Type: Vendor Advisory 43825 Source: CONFIRM Type: UNKNOWN http://support.novell.com/security/cve/CVE-2011-0468.html Source: CCN Type: Novell Web site aaa_base Source: OSVDB Type: UNKNOWN 71253 Source: CCN Type: OSVDB ID: 71253 openSUSE aaa_base Metacharacter Tab Expansion Filename Handling Command Execution Source: BID Type: UNKNOWN 46983 Source: CCN Type: BID-46983 openSUSE 'aaa_base' Package Tab Expansion Local Privilege-Escalation Vulnerability Source: CONFIRM Type: UNKNOWN https://bugzilla.novell.com/678827 Source: XF Type: UNKNOWN aaabase-filename-privilege-escalation(66245) Source: XF Type: UNKNOWN aaabase-filename-privilege-escalation(66245) Source: CCN Type: openSUSE-SU-2011:0207-1 aaa_base security update Source: SUSE Type: SUSE-SR:2011:005 SUSE Security Summary Report | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |