CVE-2005-0392: High severity Debian Ppxp vulnerability
Published May 19, 2005
·Updated
ppxp does not drop root privileges before opening log files, which allows local users to execute arbitrary commands.
Affected Software
1 affected component
Debian Ppxp
Event History
May 19, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0392?
CVE-2005-0392 has a medium severity rating due to its potential to allow local users to execute arbitrary commands.
2
How do I fix CVE-2005-0392?
To fix CVE-2005-0392, ensure that the Ppxp application is configured to drop root privileges before accessing log files.
3
Which versions are affected by CVE-2005-0392?
CVE-2005-0392 affects all versions of Ppxp included in the Debian distribution.
4
Is CVE-2005-0392 exploitable remotely?
CVE-2005-0392 is not remotely exploitable as it requires local access to the system.
5
What potential impact does CVE-2005-0392 have?
The impact of CVE-2005-0392 includes the possibility for local users to gain elevated privileges or execute arbitrary commands on the system.