Vulnerabilities > CVE-2003-0618
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
OS | 1 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-431.NASL |
description | Paul Szabo discovered a number of similar bugs in suidperl, a helper program to run perl scripts with setuid privileges. By exploiting these bugs, an attacker could abuse suidperl to discover information about files (such as testing for their existence and some of their permissions) that should not be accessible to unprivileged users. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15268 |
published | 2004-09-29 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15268 |
title | Debian DSA-431-1 : perl - information leak |
code |
|
Statements
contributor | Mark J Cox |
lastmodified | 2006-09-19 |
organization | Red Hat |
statement | Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=114923 The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: http://www.redhat.com/security/updates/classification/ This issue does not affect Red Hat Enterprise Linux 4. |
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203426
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203426
- http://www.debian.org/security/2004/dsa-431
- http://www.debian.org/security/2004/dsa-431
- http://www.securityfocus.com/bid/9543
- http://www.securityfocus.com/bid/9543
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15012
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15012