7.2
CVSSv2

CVE-2002-0817

Published: 12/08/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Format string vulnerability in super for Linux allows local users to gain root privileges via a long command line argument.

Vulnerable Product Search on Vulmon Subscribe to Product

william deich super 3.12

william deich super 3.16

william deich super 3.17

william deich super 3.18

Vendor Advisories

GOBBLES found an insecure use of format strings in the super package The included program super is intended to provide access to certain system users for particular users and programs, similar to the program sudo Exploiting this format string vulnerability a local user can gain unauthorized root access This problem has been fixed in version 312 ...

Exploits

source: wwwsecurityfocuscom/bid/5367/info super is prone to a format string vulnerability This problem is due to incorrect use of the syslog() function to log error messages It is possible to corrupt memory by passing format strings through the vulnerable logging function This may potentially be exploited to overwrite arbitrary locatio ...