First published: Thu Jul 09 2009(Updated: )
Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OCS Inventory NG | =1.0 | |
OCS Inventory NG Ocsinventory-Agent | =0.05 | |
OCS Inventory NG Ocsinventory-Agent | =0.08 | |
OCS Inventory NG | =1.0-beta | |
OCS Inventory NG Ocsinventory-Agent | <=0.0.9.2 | |
OCS Inventory NG | =1.0-rc3-1 | |
OCS Inventory NG | =1.0-rc1 | |
OCS Inventory NG | =1.0-rc3 | |
OCS Inventory NG | =1.0-rc2 | |
OCS Inventory NG Ocsinventory-Agent | =0.09 | |
OCS Inventory NG | <=0.0.9.2 | |
OCS Inventory NG | =0.05 | |
OCS Inventory NG | =0.08 | |
OCS Inventory NG | =0.09 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0667 has a moderate severity rating due to the potential for local privilege escalation.
To fix CVE-2009-0667, upgrade to Ocsinventory-Agent version 0.0.9.3 or later.
CVE-2009-0667 affects local users of Ocsinventory-Agent versions prior to 0.0.9.3 and 1.x versions prior to 1.0.1.
CVE-2009-0667 is caused by an untrusted search path in the Agent/Backend.pm module allowing arbitrary module loading.
CVE-2009-0667 cannot be exploited remotely as it requires local user access to exploit.