← Volver a CVEs
CVE-2011-0532
N/ADescripcion
The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Server 8.2.x) place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado2/23/2011
Ultima modificacion4/29/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
fedoraproject:389_directory_serverredhat:directory_server
Debilidades (CWE)
CWE-264
Referencias
http://www.redhat.com/support/errata/RHSA-2011-0293.html(secalert@redhat.com)
http://www.securityfocus.com/bid/46489(secalert@redhat.com)
http://www.securitytracker.com/id?1025102(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=672468(secalert@redhat.com)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65637(secalert@redhat.com)
http://www.redhat.com/support/errata/RHSA-2011-0293.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/46489(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id?1025102(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=672468(af854a3a-2127-422b-91ae-364da2661108)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65637(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.