CVE-2003-0084

critical

Description

mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/11893

http://www.securityfocus.com/bid/7448

http://www.redhat.com/support/errata/RHSA-2003-113.html

http://www.itlab.musc.edu/webNIS/mod_auth_any.html

http://www.ciac.org/ciac/bulletins/n-090.shtml

http://rhn.redhat.com/errata/RHSA-2003-114.html

Details

Source: Mitre, NVD

Published: 2003-05-12

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical