CVE-2009-0667: High severity Ocsinventory-ng Ocs Inventory Ng vulnerability
Published Jul 9, 2009
·Updated
Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.
Affected Software
10 affected components
Ocsinventory-ng Ocs Inventory Ng=1.0
Ocsinventory-ng Ocsinventory-agent=0.05
Ocsinventory-ng Ocsinventory-agent=0.08
Ocsinventory-ng Ocs Inventory Ng=1.0-beta
Ocsinventory-ng Ocsinventory-agent<=0.0.9.2
Ocsinventory-ng Ocs Inventory Ng=1.0-rc3-1
Ocsinventory-ng Ocs Inventory Ng=1.0-rc1
Ocsinventory-ng Ocs Inventory Ng=1.0-rc3
Ocsinventory-ng Ocs Inventory Ng=1.0-rc2
Ocsinventory-ng Ocsinventory-agent=0.09
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jul 9, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-0667?
CVE-2009-0667 has a moderate severity rating due to the potential for local privilege escalation.
2
How do I fix CVE-2009-0667?
To fix CVE-2009-0667, upgrade to Ocsinventory-Agent version 0.0.9.3 or later.
3
Who is affected by CVE-2009-0667?
CVE-2009-0667 affects local users of Ocsinventory-Agent versions prior to 0.0.9.3 and 1.x versions prior to 1.0.1.
4
What causes CVE-2009-0667?
CVE-2009-0667 is caused by an untrusted search path in the Agent/Backend.pm module allowing arbitrary module loading.
5
Can CVE-2009-0667 be exploited remotely?
CVE-2009-0667 cannot be exploited remotely as it requires local user access to exploit.