PT-2008-3847 · Red Hat · System-Config-Network

Tomas Hoger

·

Published

2008-06-02

·

Updated

2017-08-08

·

CVE-2008-2359

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: system-config-network versions prior to 1.5.10-1
Description: The default configuration of consolehelper in system-config-network lacks the USER=root directive, allowing local users of the workstation console to gain privileges and change the network configuration.
Recommendations: For system-config-network versions prior to 1.5.10-1, update to version 1.5.10-1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2359

Affected Products

System-Config-Network