Executive Summary
Summary | |
---|---|
Title | MLDonkey: Privilege escalation |
Informations | |||
---|---|---|---|
Name | GLSA-200710-25 | First vendor Publication | 2007-10-24 |
Vendor | Gentoo | Last vendor Modification | 2007-10-24 |
Severity (Vendor) | High | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Synopsis The Gentoo MLDonkey ebuild adds a user to the system with a valid login shell and no password. Background Description Impact Workaround Resolution # usermod -s /bin/false p2p NOTE: updating to the current MLDonkey ebuild will not remove this vulnerability, it must be fixed manually. The updated ebuild is to prevent this problem from occurring in the future. Availability http://security.gentoo.org/glsa/glsa-200710-25.xml |
Original Source
Url : http://security.gentoo.org/glsa/glsa-200710-25.xml |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-287 | Improper Authentication |
OpenVAS Exploits
Date | Description |
---|---|
2008-09-24 | Name : Gentoo Security Advisory GLSA 200710-25 (mldonkey) File : nvt/glsa_200710_25.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
38627 | MLDonkey on Gentoo Linux Default Unpassworded p2p Account |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-10-25 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200710-25.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:35:13 |
|