Lucene search

K
nvd[email protected]NVD:CVE-2005-4790
HistoryDec 31, 2005 - 5:00 a.m.

CVE-2005-4790

2005-12-3105:00:00
web.nvd.nist.gov
6

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

27.8%

Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.

Affected configurations

Nvd
Node
novellsuse_linuxMatch10.0
OR
susesuse_linuxMatch9.3
VendorProductVersionCPE
novellsuse_linux10.0cpe:2.3:o:novell:suse_linux:10.0:*:*:*:*:*:*:*
susesuse_linux9.3cpe:2.3:o:suse:suse_linux:9.3:*:*:*:*:*:*:*

References

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

27.8%