7.2
CVSSv2

CVE-2003-0188

Published: 09/06/2003 Updated: 11/10/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.

Vulnerable Product Search on Vulmon Subscribe to Product

lv lv 4.49.3

lv lv 4.49.4

redhat lv 4.49.4-9

lv lv 4.49.1

lv lv 4.49.2

redhat lv 4.49.4-1

redhat lv 4.49.4-3

redhat lv 4.49.4-7

redhat linux 7.3

redhat linux 8.0

redhat linux 7.1

redhat linux 7.2

redhat linux 9.0

Vendor Advisories

Leonard Stiles discovered that lv, a multilingual file viewer, would read options from a configuration file in the current directory Because such a file could be placed there by a malicious user, and lv configuration options can be used to execute commands, this represented a security vulnerability An attacker could gain the privileges of the use ...