4.6
CVSSv2

CVE-2008-2230

Published: 11/06/2008 Updated: 08/08/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Untrusted search path vulnerability in (1) reportbug 3.8 and 3.31, and (2) reportbug-ng prior to 0.2008.06.04, allows local users to execute arbitrary code via a malicious module file in the current working directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

reportbug-ng reportbug-ng 0.2007.03.17

reportbug-ng reportbug-ng 0.2007.03.19

reportbug-ng reportbug-ng 0.2007.04.07

reportbug-ng reportbug-ng 0.2007.04.07.2

reportbug-ng reportbug-ng 0.2007.05.28

reportbug-ng reportbug-ng 0.2007.05.31

reportbug-ng reportbug-ng 0.2007.08.02

reportbug-ng reportbug-ng 0.2007.08.03

reportbug-ng reportbug-ng 0.2008.03.28

reportbug-ng reportbug 3.31

reportbug-ng reportbug 3.8

reportbug-ng reportbug-ng 0.2007.03.11

reportbug-ng reportbug-ng 0.2007.03.13

reportbug-ng reportbug-ng 0.2007.03.24

reportbug-ng reportbug-ng 0.2007.03.27

reportbug-ng reportbug-ng 0.2007.04.23

reportbug-ng reportbug-ng 0.2007.03.10

reportbug-ng reportbug-ng 0.2007.03.19.2

reportbug-ng reportbug-ng 0.2007.03.20

reportbug-ng reportbug-ng 0.2007.04.13

reportbug-ng reportbug-ng 0.2007.04.16

reportbug-ng reportbug-ng 0.2007.04.20

reportbug-ng reportbug-ng 0.2007.06.13

reportbug-ng reportbug-ng 0.2007.06.27

reportbug-ng reportbug-ng 0.2007.08.03.2

reportbug-ng reportbug-ng 0.2007.08.12

reportbug-ng reportbug-ng 0.2007.04.27

reportbug-ng reportbug-ng 0.2007.07.08

reportbug-ng reportbug-ng 0.2007.07.12

reportbug-ng reportbug-ng 0.2007.08.20

reportbug-ng reportbug-ng 0.2007.10.30

reportbug-ng reportbug-ng 0.2007.03.14

reportbug-ng reportbug-ng 0.2007.03.15

reportbug-ng reportbug-ng 0.2007.03.28

reportbug-ng reportbug-ng 0.2007.03.29

reportbug-ng reportbug-ng 0.2007.05.02

reportbug-ng reportbug-ng 0.2007.05.27

reportbug-ng reportbug-ng 0.2007.07.18

reportbug-ng reportbug-ng 0.2007.07.19

reportbug-ng reportbug-ng 0.2008.01.20

reportbug-ng reportbug-ng 0.2008.03.26

Vendor Advisories

Debian Bug report logs - #484311 reportbug: CVE-2008-2230 code execution by preparing module files in oscurdir Package: reportbug; Maintainer for reportbug is Reportbug Maintainers <debian-reportbug@listsdebianorg>; Source for reportbug is src:reportbug (PTS, buildd, popcon) Reported by: Thomas Arendsen Hein <thomas@in ...