4.9
CVSSv2

CVE-2010-1457

Published: 12/05/2010 Updated: 12/05/2010
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 495
Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Tools/gdomap.c in gdomap in GNUstep Base prior to 1.20.0 allows local users to read arbitrary files via a (1) -c or (2) -a option, which prints file contents in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

gnustep gnustep base

gnustep gnustep base 1.19.1

gnustep gnustep base 1.15.0

gnustep gnustep base 1.13.0

gnustep gnustep base 1.12.0

gnustep gnustep base 1.11.2

gnustep gnustep base 1.18.0

gnustep gnustep base 1.17.0

gnustep gnustep base 1.15.4

gnustep gnustep base 1.15.2

gnustep gnustep base 1.19.2

gnustep gnustep base 1.19.0

gnustep gnustep base 1.15.1

gnustep gnustep base 1.14.0

Vendor Advisories

Debian Bug report logs - #584401 CVE-2010-1620: Integer overflow Package: gnustep-base; Maintainer for gnustep-base is Debian GNUstep maintainers <pkg-gnustep-maintainers@listsaliothdebianorg>; Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Thu, 3 Jun 2010 10:45:01 UTC Severity: serious Tags: security ...
Debian Bug report logs - #584402 CVE-2010-1457: allows local users to read arbitrary files Package: gnustep-base; Maintainer for gnustep-base is Debian GNUstep maintainers <pkg-gnustep-maintainers@listsaliothdebianorg>; Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Thu, 3 Jun 2010 10:51:01 UTC Severi ...

Exploits

source: wwwsecurityfocuscom/bid/40005/info gdomap is prone to multiple local information-disclosure vulnerabilities Local attackers can exploit these issues to obtain sensitive information that may lead to further attacks The following example commands are available: $ gdomap -c /etc/shadow $ gdomap -a /etc/shadow ...