Vulnerability Description
PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications, which allows local users to gain privileges via a sudo command that leverages access to the qmailq account.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pineapp | Mail-Secure 5099Sk | <= - |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/fulldisclosure/2013-11/0139.htmlExploit
- http://archives.neohapsis.com/archives/fulldisclosure/2013-11/0139.htmlExploit
FAQ
What is CVE-2013-6831?
CVE-2013-6831 is a vulnerability with a CVSS score of 7.2 (HIGH). PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications, which allows local users to gain privileges via a sudo comm...
How severe is CVE-2013-6831?
CVE-2013-6831 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-6831?
Check the references section above for vendor advisories and patch information. Affected products include: Pineapp Mail-Secure 5099Sk.