Lucene search

K
cve[email protected]CVE-2009-3894
HistoryNov 29, 2009 - 1:07 p.m.

CVE-2009-3894

2009-11-2913:07:52
web.nvd.nist.gov
28
cve
2009
3894
untrusted search path
vulnerabilities
dstat
python module
local users
privileges

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

25.8%

Multiple untrusted search path vulnerabilities in dstat before 0.7.0 allow local users to gain privileges via a Trojan horse Python module in (1) the current working directory or (2) a certain subdirectory of the current working directory.

Affected configurations

NVD
Node
dag.wieersdstatRange≀0.6.9
OR
dag.wieersdstatMatch0.1
OR
dag.wieersdstatMatch0.2
OR
dag.wieersdstatMatch0.3
OR
dag.wieersdstatMatch0.4
OR
dag.wieersdstatMatch0.5
OR
dag.wieersdstatMatch0.5.2
OR
dag.wieersdstatMatch0.5.3
OR
dag.wieersdstatMatch0.5.4
OR
dag.wieersdstatMatch0.5.5
OR
dag.wieersdstatMatch0.5.6
OR
dag.wieersdstatMatch0.5.7
OR
dag.wieersdstatMatch0.5.8
OR
dag.wieersdstatMatch0.5.9
OR
dag.wieersdstatMatch0.5.10
OR
dag.wieersdstatMatch0.6.0
OR
dag.wieersdstatMatch0.6.1
OR
dag.wieersdstatMatch0.6.2
OR
dag.wieersdstatMatch0.6.3
OR
dag.wieersdstatMatch0.6.4
OR
dag.wieersdstatMatch0.6.5
OR
dag.wieersdstatMatch0.6.6
OR
dag.wieersdstatMatch0.6.7
OR
dag.wieersdstatMatch0.6.8

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

25.8%