CVE-2013-4482
published 2013-11-23CVE-2013-4482: Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain…
PriorityP418medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.38%
30.5th percentile
Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain privileges via a Trojan horse .egg-info file in the (1) current working directory or (2) its parent directories.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| scientificlinux | luci | — | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
luci: paster hidden untrusted path and "command" (callable association) injection
vendor_redhat·2013-11-20·CVSS 6.2
CVE-2013-4482 [MEDIUM] luci: paster hidden untrusted path and "command" (callable association) injection
luci: paster hidden untrusted path and "command" (callable association) injection
Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain privileges via a Trojan horse .egg-info file in the (1) current working directory or (2) its parent directories.
A flaw was found in the way the luci service was initialized. If a system administrator started the luci service from a directory that was writable to by a local user, that user could use this flaw to execute arbitrary code as the root or luci user.
Package: conga (Red Hat Enterprise Linux 5) - Not affected
GHSA
GHSA-f585-5p5j-mvf8: Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0
ghsa_unreviewed·2022-05-14
CVE-2013-4482 [MEDIUM] GHSA-f585-5p5j-mvf8: Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0
Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain privileges via a Trojan horse .egg-info file in the (1) current working directory or (2) its parent directories.
No detection rules found.
No public exploits indexed.
2013-11-23
Published