Lucene search

K
nvd[email protected]NVD:CVE-2004-1452
HistoryDec 31, 2004 - 5:00 a.m.

CVE-2004-1452

2004-12-3105:00:00
web.nvd.nist.gov
2

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

High

EPSS

0

Percentile

5.1%

Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.

Affected configurations

Nvd
Node
gentoolinuxMatch0.5
OR
gentoolinuxMatch0.7
OR
gentoolinuxMatch1.1a
OR
gentoolinuxMatch1.2
OR
gentoolinuxMatch1.4
OR
gentoolinuxMatch1.4rc1
OR
gentoolinuxMatch1.4rc2
OR
gentoolinuxMatch1.4rc3
VendorProductVersionCPE
gentoolinux0.5cpe:2.3:o:gentoo:linux:0.5:*:*:*:*:*:*:*
gentoolinux0.7cpe:2.3:o:gentoo:linux:0.7:*:*:*:*:*:*:*
gentoolinux1.1acpe:2.3:o:gentoo:linux:1.1a:*:*:*:*:*:*:*
gentoolinux1.2cpe:2.3:o:gentoo:linux:1.2:*:*:*:*:*:*:*
gentoolinux1.4cpe:2.3:o:gentoo:linux:1.4:*:*:*:*:*:*:*
gentoolinux1.4cpe:2.3:o:gentoo:linux:1.4:rc1:*:*:*:*:*:*
gentoolinux1.4cpe:2.3:o:gentoo:linux:1.4:rc2:*:*:*:*:*:*
gentoolinux1.4cpe:2.3:o:gentoo:linux:1.4:rc3:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

High

EPSS

0

Percentile

5.1%

Related for NVD:CVE-2004-1452