René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

87 lines
2.6 KiB
JSON

{
"id": "CVE-2009-1648",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-07-05T16:30:00.327",
"lastModified": "2009-07-06T04:00:00.000",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances involving reboots during online updates, which makes it easier for remote attackers to access network services."
},
{
"lang": "es",
"value": "El m\u00f3dulo YaST2 LDAP de yast2-ldap-server de SUSE Linux Enterprise Server v11 -tambi\u00e9n conocido como SLE11-, no activa el cortafuegos en determinadas circunstancias que incluyen reinicios durante las actualizaciones en l\u00ednea, esto facilita a los atacantes remotos acceder a los servicios en red."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-16"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:suse:suse_linux:11:*:enterprise_desktop:*:*:*:*:*",
"matchCriteriaId": "A21C44DE-B976-437F-99F0-C4BB018C3121"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:suse:suse_linux:11:*:enterprise_server:*:*:*:*:*",
"matchCriteriaId": "B34E5287-ED2F-4BE2-8166-52B0108DCEC3"
}
]
}
]
}
],
"references": [
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
}
]
}