Vulnerability Description
mod_ruid2 before 0.9.8 improperly handles file descriptors which allows remote attackers to bypass security using a CGI script to break out of the chroot.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mod Ruid2 Project | Mod Ruid2 | < 0.9.8 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2013/03/23/1Mailing ListThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83035Third Party AdvisoryVDB Entry
- https://security-tracker.debian.org/tracker/CVE-2013-1889Third Party Advisory
- https://sourceforge.net/p/mod-ruid/mailman/mod-ruid-announce/thread/514C503E.402
- http://www.openwall.com/lists/oss-security/2013/03/23/1Mailing ListThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83035Third Party AdvisoryVDB Entry
- https://security-tracker.debian.org/tracker/CVE-2013-1889Third Party Advisory
- https://sourceforge.net/p/mod-ruid/mailman/mod-ruid-announce/thread/514C503E.402
FAQ
What is CVE-2013-1889?
CVE-2013-1889 is a vulnerability with a CVSS score of 7.5 (HIGH). mod_ruid2 before 0.9.8 improperly handles file descriptors which allows remote attackers to bypass security using a CGI script to break out of the chroot.
How severe is CVE-2013-1889?
CVE-2013-1889 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-1889?
Check the references section above for vendor advisories and patch information. Affected products include: Mod Ruid2 Project Mod Ruid2.