7.2
CVSSv2

CVE-2009-0667

Published: 09/07/2009 Updated: 07/11/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent prior to 0.0.9.3, and 1.x prior to 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ocsinventory-ng ocs inventory ng 1.0

ocsinventory-ng ocsinventory-agent 0.05

ocsinventory-ng ocsinventory-agent 0.08

ocsinventory-ng ocsinventory-agent

ocsinventory-ng ocsinventory-agent 0.09

Vendor Advisories

It was discovered that the ocsinventory-agent which is part of the ocsinventory suite, a hardware and software configuration indexing service, is prone to an insecure perl module search path As the agent is started via cron and the current directory (/ in this case) is included in the default perl module path the agent scans every directory on the ...