Vulnerability Description
Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ocsinventory-Ng | Ocs Inventory Ng | 1.0 |
| Ocsinventory-Ng | Ocsinventory-Agent | <= 0.0.9.2 |
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506416Patch
- http://nana.rulezlan.org/~goneri/ocsinventory-agent/Ocsinventory-Agent-0.0.9.3.tPatch
- http://osvdb.org/55718
- http://secunia.com/advisories/35727
- http://secunia.com/advisories/35768
- http://security.debian.org/pool/updates/main/o/ocsinventory-agent/ocsinventory-aPatch
- http://www.debian.org/security/2009/dsa-1828Patch
- http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt0
- http://www.securityfocus.com/bid/35593Patch
- http://www.vupen.com/english/advisories/2009/1809PatchVendor Advisory
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506416Patch
- http://nana.rulezlan.org/~goneri/ocsinventory-agent/Ocsinventory-Agent-0.0.9.3.tPatch
- http://osvdb.org/55718
- http://secunia.com/advisories/35727
- http://secunia.com/advisories/35768
FAQ
What is CVE-2009-0667?
CVE-2009-0667 is a vulnerability with a CVSS score of 7.2 (HIGH). Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl modul...
How severe is CVE-2009-0667?
CVE-2009-0667 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0667?
Check the references section above for vendor advisories and patch information. Affected products include: Ocsinventory-Ng Ocs Inventory Ng, Ocsinventory-Ng Ocsinventory-Agent.