Vulnerability Description
The setgid wrapper libx2go-server-db-sqlite3-wrapper.c in X2Go Server before 4.0.0.2 allows remote attackers to execute arbitrary code via unspecified vectors, related to the path to libx2go-server-db-sqlite3-wrapper.pl.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| X2Go | X2Go Server | <= 4.0.0.1 |
Related Weaknesses (CWE)
References
- http://code.x2go.org/gitweb?p=x2goserver.git%3Ba=commit%3Bh=42264c88d7885474ebe3
- http://security.gentoo.org/glsa/glsa-201310-19.xml
- http://www.openwall.com/lists/oss-security/2013/09/25/11
- https://lists.berlios.de/pipermail/x2go-announcement/2013-May/000125.htmlVendor Advisory
- http://code.x2go.org/gitweb?p=x2goserver.git%3Ba=commit%3Bh=42264c88d7885474ebe3
- http://security.gentoo.org/glsa/glsa-201310-19.xml
- http://www.openwall.com/lists/oss-security/2013/09/25/11
- https://lists.berlios.de/pipermail/x2go-announcement/2013-May/000125.htmlVendor Advisory
FAQ
What is CVE-2013-4376?
CVE-2013-4376 is a vulnerability with a CVSS score of 7.5 (HIGH). The setgid wrapper libx2go-server-db-sqlite3-wrapper.c in X2Go Server before 4.0.0.2 allows remote attackers to execute arbitrary code via unspecified vectors, related to the path to libx2go-server-db...
How severe is CVE-2013-4376?
CVE-2013-4376 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4376?
Check the references section above for vendor advisories and patch information. Affected products include: X2Go X2Go Server.