6.9
CVSSv2

CVE-2010-2945

Published: 30/08/2010 Updated: 31/08/2010
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The default configuration of SLiM prior to 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp.

Vulnerable Product Search on Vulmon Subscribe to Product

simone rota slim simple login manager 1.2.1

simone rota slim simple login manager 1.2.0

simone rota slim simple login manager 1.1.0

simone rota slim simple login manager 1.0.0

simone rota slim simple login manager 1.2.5

simone rota slim simple login manager 1.2.3

simone rota slim simple login manager 1.3.0

simone rota slim simple login manager 1.2.6

simone rota slim simple login manager 1.2.4

simone rota slim simple login manager 1.2.2

simone rota slim simple login manager

Vendor Advisories

Debian Bug report logs - #594414 CVE-2010-2945: insecure PATH assignment Package: slim; Maintainer for slim is Nobuhiro Iwamatsu <iwamatsu@debianorg>; Source for slim is src:slim (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 25 Aug 2010 20:03:02 UTC Severity: grave Tags: security ...