CVE-2010-2241
published 2010-08-17CVE-2010-2241: The (1) setup-ds.pl and (2) setup-ds-admin.pl setup scripts for Red Hat Directory Server 8 before 8.2 use world-readable permissions when creating cache files…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.35%
27.4th percentile
The (1) setup-ds.pl and (2) setup-ds-admin.pl setup scripts for Red Hat Directory Server 8 before 8.2 use world-readable permissions when creating cache files, which allows local users to obtain sensitive information including passwords for Directory and Administration Server administrative accounts.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
redhat-ds: setup script insecure .inf file permissions
vendor_redhat·2010-05-18·CVSS 2.1
CVE-2010-2241 [LOW] redhat-ds: setup script insecure .inf file permissions
redhat-ds: setup script insecure .inf file permissions
The (1) setup-ds.pl and (2) setup-ds-admin.pl setup scripts for Red Hat Directory Server 8 before 8.2 use world-readable permissions when creating cache files, which allows local users to obtain sensitive information including passwords for Directory and Administration Server administrative accounts.
GHSA
GHSA-g8wm-c6h5-35rm: The (1) setup-ds
ghsa_unreviewed·2022-05-14
CVE-2010-2241 [LOW] GHSA-g8wm-c6h5-35rm: The (1) setup-ds
The (1) setup-ds.pl and (2) setup-ds-admin.pl setup scripts for Red Hat Directory Server 8 before 8.2 use world-readable permissions when creating cache files, which allows local users to obtain sensitive information including passwords for Directory and Administration Server administrative accounts.
Suricata
GPL FTP SITE EXEC attempt
suricata·2010-09-23
CVE-1999-0080 GPL FTP SITE EXEC attempt
GPL FTP SITE EXEC attempt
Rule: alert ftp $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL FTP SITE EXEC attempt"; flow:established,to_server; content:"SITE"; nocase; content:"EXEC"; distance:0; nocase; pcre:"/^SITE\s+EXEC/smi"; reference:arachnids,317; reference:bugtraq,2241; reference:cve,1999-0080; reference:cve,1999-0955; classtype:bad-unknown; sid:2100361; rev:18; metadata:created_at 2010_09_23, cve CVE_1999_0080, signature_severity Unknown, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2010-0590.htmlhttp://secunia.com/advisories/40811http://www.osvdb.org/66962http://www.securitytracker.com/id?1024281https://bugzilla.redhat.com/show_bug.cgi?id=608032http://rhn.redhat.com/errata/RHSA-2010-0590.htmlhttp://secunia.com/advisories/40811http://www.osvdb.org/66962http://www.securitytracker.com/id?1024281https://bugzilla.redhat.com/show_bug.cgi?id=608032
2010-08-17
Published