CVE-2008-4313 — Redhat Enterprise Linux vulnerability
Severity
6.0MEDIUMNVD
EPSS
0.6%
top 31.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 27
Latest updateMay 2
Description
A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated users to bypass intended access restrictions and send requests to OpenPegasus WBEM services.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4
Patches
🔴Vulnerability Details
1📋Vendor Advisories
1Red Hat
▶
💬Community
1Bugzilla▶
CVE-2008-4313 tog-pegasus: WBEM services access not restricted to dedicated user after 2.7.0 rebase↗2008-08-15