PT-2014-1892 · X2Go · X2Go Server

Published

2014-05-19

·

Updated

2014-05-21

·

CVE-2013-7383

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions X2Go Server versions prior to 4.0.0.8 X2Go Server versions 4.0.1.x prior to 4.0.1.10 X2Go Server versions prior to 4.0.1.12
Description The issue allows remote authenticated users to gain privileges via unspecified vectors, possibly related to backticks. Exploitation of this issue may lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely by an attacker who has passed the authentication procedure.
Recommendations For versions prior to 4.0.0.8, update to version 4.0.0.8 or later. For versions 4.0.1.x prior to 4.0.1.10, update to version 4.0.1.10 or later. For versions prior to 4.0.1.12, update to version 4.0.1.12 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09757
CVE-2013-7383

Affected Products

X2Go Server