PT-2003-1356 · Red Hat+1 · Red Hat+1
Daniel Jarboe
+1
·
Publicado
2003-04-29
·
Atualizado
2017-07-11
·
CVE-2003-0084
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat Enterprise Linux version 2.1
mod auth any (affected versions not specified)
Description
The issue is related to the mod auth any package, which does not properly escape arguments when calling other programs. This allows attackers to execute arbitrary commands via shell metacharacters.
Recommendations
For Red Hat Enterprise Linux version 2.1, update the mod auth any package to a version that properly escapes arguments.
For mod auth any, consider disabling the execution of external programs until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat
Mod Auth Any