Описание
The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp.
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | DNE | |
| devel | not-affected | 1.3.1-7 |
| hardy | ignored | end of life |
| jaunty | ignored | end of life |
| karmic | DNE | |
| lucid | ignored | end of life |
| maverick | not-affected | 1.3.1-7 |
| natty | not-affected | 1.3.1-7 |
| oneiric | not-affected | 1.3.1-7 |
| precise | not-affected | 1.3.1-7 |
Показывать по
Ссылки на источники
6.9 Medium
CVSS2
Связанные уязвимости
The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp.
The default configuration of SLiM before 1.3.2 places ./ (dot slash) a ...
The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp.
6.9 Medium
CVSS2