2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2004-0793" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2004-10-20T04:00:00.000" ,
"lastModified" : "2017-07-11T01:30:28.730" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file."
} ,
{
"lang" : "es" ,
"value" : "El programa de calendario en bsdmainutils 6.0 a 6.0.14 cuando se ejecuta con la opci\u00f3n -a, no suelta los privilegios de root, lo que permite a atacantes ejecutar \u00f3rdenes de su elecci\u00f3n mediante un cierto fichero de evento de calendario."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C" ,
"accessVector" : "LOCAL" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "COMPLETE" ,
"integrityImpact" : "COMPLETE" ,
"availabilityImpact" : "COMPLETE" ,
"baseScore" : 7.2
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 10.0 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : true ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-264"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "33F7B97D-4411-4F01-B969-BA06CEBB816E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CBB4D25B-CF20-484B-8570-ABA6F2468F91"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2357F328-0629-46B3-8E70-3C19C7F0DFC0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C008A9A0-C348-42F3-A436-D3B085FDF4D3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0BB1896A-72CC-4E8F-875D-BAA7E2296B49"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "12224CB6-0A54-432C-B8D4-F51843938C5D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A740E9E8-7401-49A2-B745-CBC89A98E0D7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B5A7B389-6593-4578-B342-313227382F96"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8CF7BB82-1111-4C4A-A899-FD33C8A798A2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "96C547C1-0363-4B19-9DF8-A3F0BB10F587"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2A9B8C42-9311-4A95-A120-ABC24F4122BC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.11:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7B069BF2-5E87-47BC-A330-CB12D9DC63CE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.12:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "22EBA80D-1968-4913-90D4-CFDCE888E96D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.13:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1417390C-4C78-4ED1-8FD8-158B1E064103"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:debian:bsdmainutils:6.0.14:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FCA90C16-50D9-4368-AE14-00910F5D55C6"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://marc.info/?l=bugtraq&m=109396230317359&w=2" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.securityfocus.com/bid/11077" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Exploit" ,
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/17162" ,
"source" : "cve@mitre.org"
}
]
}