7.2
CVSSv2

CVE-2011-1760

Published: 09/06/2011 Updated: 07/09/2011
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

utils/opcontrol in OProfile 0.9.6 and previous versions might allow local users to conduct eval injection attacks and gain privileges via shell metacharacters in the -e argument.

Vulnerable Product Search on Vulmon Subscribe to Product

maynard johnson oprofile 0.6.1

maynard johnson oprofile 0.8.1

maynard johnson oprofile 0.9.4

maynard johnson oprofile 0.9.5

maynard johnson oprofile

maynard johnson oprofile 0.1

maynard johnson oprofile 0.7

maynard johnson oprofile 0.7.1

maynard johnson oprofile 0.5.4

maynard johnson oprofile 0.4

maynard johnson oprofile 0.5.2

maynard johnson oprofile 0.5.1

maynard johnson oprofile 0.9.2

maynard johnson oprofile 0.9.3

maynard johnson oprofile 0.8.2

maynard johnson oprofile 0.2

maynard johnson oprofile 0.5.3

maynard johnson oprofile 0.5

maynard johnson oprofile 0.8

maynard johnson oprofile 0.9

maynard johnson oprofile 0.9.1

maynard johnson oprofile 0.3

maynard johnson oprofile 0.6

Vendor Advisories

OProfile could be made to run programs as an administrator ...

Exploits

source: wwwsecurityfocuscom/bid/47652/info OProfile is prone to a local privilege-escalation vulnerability An attacker can exploit this issue to run arbitrary commands with superuser privileges The following example command is available: sudo opcontrol -e "abcd;/usr/bin/id" ...