Описание
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modify access restrictions in hosts.deny and gain root privileges by creating the temporary files before automatic IP blocking is performed.
Ссылки
- Exploit
- Exploit
- PatchVendor Advisory
- Exploit
- Exploit
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.8.0 (включая)
cpe:2.3:a:ossec:ossec:*:*:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.09659
Низкий
7.2 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
debian
около 11 лет назад
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with pred ...
github
больше 3 лет назад
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modify access restrictions in hosts.deny and gain root privileges by creating the temporary files before automatic IP blocking is performed.
EPSS
Процентиль: 93%
0.09659
Низкий
7.2 High
CVSS2
Дефекты
CWE-264