7.2
CVSSv2

CVE-2011-2489

Published: 27/07/2011 Updated: 07/09/2011
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple off-by-one errors in opiesu.c in opiesu in OPIE 2.4.1-test1 and previous versions might allow local users to gain privileges via a crafted command line.

Vulnerable Product Search on Vulmon Subscribe to Product

nrl opie 2.3

nrl opie 2.22

nrl opie 2.21

nrl opie 2.2

nrl opie

nrl opie 2.11

nrl opie 2.10

nrl opie 2.32

nrl opie 2.4

Vendor Advisories

Sebastian Krahmer discovered that opie, a system that makes it simple to use One-Time passwords in applications, is prone to a privilege escalation (CVE-2011-2490) and an off-by-one error, which can lead to the execution of arbitrary code (CVE-2011-2489) Adam Zabrocki and Maksymilian Arciemowicz also discovered another off-by-one error (CVE-2010-1 ...