CVE-2005-0503

6 documents6 sources
Severity
4.6MEDIUM
EPSS
0.1%
top 79.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 21
Latest updateMay 1

Description

uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages3 packages

Debianuim< 1:0.4.6beta2-1+3
NVDuim/uim0.4.5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-p5v6-j4pp-pf2r: uim before 02022-05-01
CVEList
CVE-2005-0503: uim before 02005-02-21
OSV
CVE-2005-0503: uim before 02005-02-21

💥Exploits & PoCs

1
Exploit-DB
paNews 2.0b4 - Remote Admin Creation SQL Injection2005-03-08

📋Vendor Advisories

1
Debian
CVE-2005-0503: uim - uim before 0.4.5.1 trusts certain environment variables when libUIM is used in s...2005
CVE-2005-0503 (MEDIUM CVSS 4.6) | uim before 0.4.5.1 trusts certain e | cvebase.io