VDB
CVE-2011-1946
CVE-2011-1946
PUBLISHED
CVSS 7.199999809265137 HIGH
gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid function, which allows local users to gain privileges by leveraging access to two unprivileged user accounts, and running many processes under one of these accounts.
EPSS 0.36% · 28.5th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
0.36%
28.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| hongli_lai | libgnomesu | 1.0.0 |
Timeline
- Jul 7, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- [oss-security] 20110531 Re: CVE request: libgnomesu privilege escalation mailing-list
- http://openwall.com/lists/oss-security/2011/05/30/2 patch
- http://www.securityfocus.com/bid/48035 technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67720 technical
- https://nvd.nist.gov/vuln/detail/CVE-2011-1946 advisory
- https://bugzilla.novell.com/show_bug.cgi?id=695627 url