4.6
CVSSv2

CVE-2003-0452

Published: 07/08/2003 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflows in osh prior to 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections."

Vulnerable Product Search on Vulmon Subscribe to Product

gunnar ritter osh

Vendor Advisories

Steve Kemp discovered that osh, a shell intended to restrict the actions of the user, contains two buffer overflows, in processing environment variables and file redirections These vulnerabilities could be used to execute arbitrary code, overriding any restrictions placed on the shell For the stable distribution (woody) this problem has been fixe ...