CVE-2011-0532

CWE-2645 documents5 sources
Severity
6.2MEDIUM
EPSS
0.0%
top 85.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 23
Latest updateMay 17

Description

The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Server 8.2.x) place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

CVSS vector

AV:L/AC:H/C:C/I:C/A:CExploitability: 1.9 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-pw8c-3x98-r358: The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 12022-05-17
CVEList
CVE-2011-0532: The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 12011-02-23

📋Vendor Advisories

1
Red Hat
Server: use of insecure LD_LIBRARY_PATH settings2011-02-22

💬Community

1
Bugzilla
CVE-2011-0532 Directory Server: use of insecure LD_LIBRARY_PATH settings2011-01-25
CVE-2011-0532 (MEDIUM CVSS 6.2) | The (1) backup and restore scripts | cvebase.io