Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-2133

Опубликовано: 29 янв. 2004
Источник: nvd
CVSS2: 4.6
EPSS Низкий

Описание

Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cvsup:cvsup:cvsup-16.1h-2.i386.rpm:*:*:*:*:*:*:*
cpe:2.3:a:cvsup:cvsup:cvsup-16.1h-36.i586.rpm:*:*:*:*:*:*:*
cpe:2.3:a:cvsup:cvsup:cvsup-16.1h-43.i586.rpm:*:*:*:*:*:*:*

EPSS

Процентиль: 23%
0.00078
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages.

EPSS

Процентиль: 23%
0.00078
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other