| Vulnerability Name: | CVE-2011-1496 (CCN-66693) | ||||||||||||
| Assigned: | 2011-04-11 | ||||||||||||
| Published: | 2011-04-11 | ||||||||||||
| Updated: | 2017-08-17 | ||||||||||||
| Summary: | tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a filename to the -S command-line option. | ||||||||||||
| CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||
| CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||
| Vulnerability Type: | CWE-264 | ||||||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2011-1496 Source: FEDORA Type: UNKNOWN FEDORA-2011-5167 Source: FEDORA Type: UNKNOWN FEDORA-2011-5156 Source: FEDORA Type: UNKNOWN FEDORA-2011-5486 Source: SECUNIA Type: Vendor Advisory 44081 Source: SECUNIA Type: Vendor Advisory 44239 Source: CCN Type: tmux Web site tmux Source: DEBIAN Type: UNKNOWN DSA-2212 Source: DEBIAN Type: DSA-2212 tmux -- privilege escalation Source: EXPLOIT-DB Type: Exploit 17147 Source: CCN Type: OSVDB ID: 71883 tmux Group Privilege Dropping Weakness Local Privilege Escalation Source: BID Type: UNKNOWN 47283 Source: CCN Type: BID-47283 tmux '-S' Option Incorrect SetGID Local Privilege Escalation Vulnerability Source: VUPEN Type: Vendor Advisory ADV-2011-0897 Source: VUPEN Type: Vendor Advisory ADV-2011-1002 Source: VUPEN Type: Vendor Advisory ADV-2011-1015 Source: XF Type: UNKNOWN tmux-setgid-privilege-escalation(66693) Source: XF Type: UNKNOWN tmux-setgid-privilege-escalation(66693) Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [04-11-2011] | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||