Vulnerability Details CVE-2011-0532
The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Server 8.2.x) place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.3%
CVSS Severity
CVSS v2 Score 6.2
Products affected by CVE-2011-0532
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.1
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.2
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.3
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.5
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6.1
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.7
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.7.5
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.8
-
cpe:2.3:a:redhat:directory_server:8.2
-
cpe:2.3:a:redhat:directory_server:8.2.3