cbcvebase.
CVE-2011-0532
published 2011-02-23

CVE-2011-0532: The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Server…

PriorityP420medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.28%
20.4th percentile
The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Server 8.2.x) place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Affected

11 ranges
VendorProductVersion rangeFixed in
fedoraproject389_directory_server
fedoraproject389_directory_server
fedoraproject389_directory_server
fedoraproject389_directory_server
fedoraproject389_directory_server
fedoraproject389_directory_server
fedoraproject389_directory_server
fedoraproject389_directory_server
fedoraproject389_directory_server
redhatdirectory_server
redhatdirectory_server

CVSS provenance

nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.