7.2
CVSSv2

CVE-2011-2490

Published: 27/07/2011 Updated: 07/09/2011
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

opielogin.c in opielogin in OPIE 2.4.1-test1 and previous versions does not check the return value of the setuid system call, which allows local users to gain privileges by arranging for an account to already be running its maximum number of processes.

Vulnerable Product Search on Vulmon Subscribe to Product

nrl opie 2.11

nrl opie 2.3

nrl opie 2.22

nrl opie 2.32

nrl opie 2.4

nrl opie 2.10

nrl opie 2.21

nrl opie 2.2

nrl opie

Vendor Advisories

Sebastian Krahmer discovered that opie, a system that makes it simple to use One-Time passwords in applications, is prone to a privilege escalation (CVE-2011-2490) and an off-by-one error, which can lead to the execution of arbitrary code (CVE-2011-2489) Adam Zabrocki and Maksymilian Arciemowicz also discovered another off-by-one error (CVE-2010-1 ...