7.2
CVSSv2

CVE-2008-2378

Published: 26/11/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in hfkernel in hf 0.7.3 and 0.8 allows local users to gain privileges via a Trojan horse killall program in a directory in the PATH, related to improper handling of the -k option.

Vulnerable Product Search on Vulmon Subscribe to Product

hf hf 0.7.3

hf hf 0.8

Vendor Advisories

Steve Kemp discovered that hf, an amateur-radio protocol suite using a soundcard as a modem, insecurely tried to execute an external command which could lead to the elevation of privileges for local users For the stable distribution (etch), this problem has been fixed in version 073-4etch1 For the unstable distribution (sid), this problem has b ...