PT-2014-1892 · X2Go · X2Go Server

Publicado

2014-05-19

·

Atualizado

2014-05-21

·

CVE-2013-7383

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions X2Go Server versions prior to 4.0.0.8 X2Go Server versions 4.0.1.x prior to 4.0.1.10 X2Go Server versions prior to 4.0.1.12
Description The issue allows remote authenticated users to gain privileges via unspecified vectors, possibly related to backticks. Exploitation of this issue may lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely by an attacker who has passed the authentication procedure.
Recommendations For versions prior to 4.0.0.8, update to version 4.0.0.8 or later. For versions 4.0.1.x prior to 4.0.1.10, update to version 4.0.1.10 or later. For versions prior to 4.0.1.12, update to version 4.0.1.12 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09757
CVE-2013-7383

Produtos afetados

X2Go Server