Vulnerability Name: | CVE-2013-4362 (CCN-87283) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2013-09-17 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2013-09-17 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2017-07-01 | ||||||||||||||||||||||||||||||||||||||||
Summary: | WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1) kernel_interface.c and (2) mount_davfs.c, related to the "system" function. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.6 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
3.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-4362 Source: OSVDB Type: UNKNOWN 97416 Source: OSVDB Type: UNKNOWN 97417 Source: CONFIRM Type: Patch http://savannah.nongnu.org/bugs/?40034 Source: CCN Type: DavFS2 Web site DavFS2 Source: CCN Type: oss-sec mailing list, Tue, 17 Sep 2013 10:13:40 +0200 CVE request: davfs2 - Unsecure use of system() Source: MLIST Type: Patch [oss-security] 20130918 Re: CVE request: davfs2 - Unsecure use of system() Source: DEBIAN Type: UNKNOWN DSA-2765 Source: DEBIAN Type: DSA-2765 davfs2 -- privilege escalation Source: CCN Type: OSVDB ID: 97416 WEB-DAV Linux File System (davfs2) mount_davfs system() Call Local Privilege Escalation Source: CCN Type: OSVDB ID: 97417 WEB-DAV Linux File System (davfs2) kernel_interface system() Call Local Privilege Escalation Source: BID Type: UNKNOWN 62445 Source: CCN Type: BID-62445 DavFS2 'system()' Function Local Privilege Escalation Vulnerability Source: XF Type: UNKNOWN davfs2-system-priv-esc(87283) Source: CCN Type: Packet Storm Security [10-08-2013] davfs2 1.4.6 / 1.4.7 Privilege Escalation Source: GENTOO Type: UNKNOWN GLSA-201612-02 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [10-08-2013] | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |