Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-4984

Опубликовано: 17 июл. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 1.9
CVSS3: 4.7

Описание

/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

not-affected

esm-infra/xenial

not-affected

precise

not-affected

trusty

not-affected

trusty/esm

not-affected

upstream

needs-triage

vivid/stable-phone-overlay

not-affected

vivid/ubuntu-core

not-affected

wily

not-affected

Показывать по

Ссылки на источники

EPSS

Процентиль: 6%
0.00024
Низкий

1.9 Low

CVSS2

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 2.7
redhat
больше 9 лет назад

/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.

CVSS3: 4.7
nvd
больше 8 лет назад

/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.

CVSS3: 4.7
debian
больше 8 лет назад

/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets ...

CVSS3: 4.7
github
больше 3 лет назад

/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.

EPSS

Процентиль: 6%
0.00024
Низкий

1.9 Low

CVSS2

4.7 Medium

CVSS3