6.2
CVSSv2

CVE-2011-0532

Published: 23/02/2011 Updated: 17/08/2017
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 552
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Server 8.2.x) place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject 389 directory server 1.2.6.1

fedoraproject 389 directory server 1.2.6

fedoraproject 389 directory server 1.2.5

fedoraproject 389 directory server 1.2.2

fedoraproject 389 directory server 1.2.8

fedoraproject 389 directory server 1.2.7

fedoraproject 389 directory server 1.2.7.5

fedoraproject 389 directory server 1.2.1

fedoraproject 389 directory server 1.2.3

redhat directory server 8.2.3

redhat directory server 8.2