Lucene search

K
cve[email protected]CVE-2014-0039
HistoryFeb 08, 2014 - 12:55 a.m.

CVE-2014-0039

2014-02-0800:55:06
web.nvd.nist.gov
22
cve-2014-0039
fwsnort
vulnerability
untrusted search path
local users
arbitrary code
nvd

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.3%

Untrusted search path vulnerability in fwsnort before 1.6.4, when not running as root, allows local users to execute arbitrary code via a Trojan horse fwsnort.conf in the current working directory.

Affected configurations

NVD
Node
cipherdynefwsnortRange1.6.4
OR
cipherdynefwsnortMatch0.5
OR
cipherdynefwsnortMatch0.6
OR
cipherdynefwsnortMatch0.6.1
OR
cipherdynefwsnortMatch0.6.2
OR
cipherdynefwsnortMatch0.6.3
OR
cipherdynefwsnortMatch0.6.4
OR
cipherdynefwsnortMatch0.6.5
OR
cipherdynefwsnortMatch0.7.0
OR
cipherdynefwsnortMatch0.8.0
OR
cipherdynefwsnortMatch0.8.1
OR
cipherdynefwsnortMatch0.8.2
OR
cipherdynefwsnortMatch0.9.0
OR
cipherdynefwsnortMatch1.0
OR
cipherdynefwsnortMatch1.0.1
OR
cipherdynefwsnortMatch1.0.2
OR
cipherdynefwsnortMatch1.0.3
OR
cipherdynefwsnortMatch1.0.4
OR
cipherdynefwsnortMatch1.0.5
OR
cipherdynefwsnortMatch1.0.6
OR
cipherdynefwsnortMatch1.5
OR
cipherdynefwsnortMatch1.6
OR
cipherdynefwsnortMatch1.6.1
OR
cipherdynefwsnortMatch1.6.2
OR
cipherdynefwsnortMatch1.6.3

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.3%