PT-2003-1356 · Red Hat+1 · Red Hat+1

Daniel Jarboe

+1

·

Publicado

2003-04-29

·

Atualizado

2017-07-11

·

CVE-2003-0084

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Linux version 2.1 mod auth any (affected versions not specified)
Description The issue is related to the mod auth any package, which does not properly escape arguments when calling other programs. This allows attackers to execute arbitrary commands via shell metacharacters.
Recommendations For Red Hat Enterprise Linux version 2.1, update the mod auth any package to a version that properly escapes arguments. For mod auth any, consider disabling the execution of external programs until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0084

Produtos afetados

Red Hat
Mod Auth Any