Lucene search

K
freebsdFreeBSD18A14BAA-5EE5-11DB-AE08-0008743BF21A
HistoryOct 18, 2006 - 12:00 a.m.

ingo -- local arbitrary shell command execution

2006-10-1800:00:00
vuxml.freebsd.org
9

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.006

Percentile

78.2%

The Horde team reports a vulnerability within Ingo, the
filter management suite. The vulnerability is caused due to
inadequete escaping, possibly allowing a local user to execute
arbitrary shell commands via procmail.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchingo< 1.1.2UNKNOWN

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.006

Percentile

78.2%