CVE-2011-2489: High severity nrl opie vulnerability
Published Jul 27, 2011
·Updated
Multiple off-by-one errors in opiesu.c in opiesu in OPIE 2.4.1-test1 and earlier might allow local users to gain privileges via a crafted command line.
Affected Software
9 affected components
Nrl Opie=2.3
Nrl Opie<=2.4.1
Nrl Opie=2.10
Nrl Opie=2.2
Nrl Opie=2.32
Nrl Opie=2.4
Nrl Opie=2.21
Nrl Opie=2.22
Nrl Opie=2.11
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jul 27, 2011
CVE Published
via MITRE·01:29 AM
Data Sourced
via MITRE·01:29 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2489?
CVE-2011-2489 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2011-2489?
To fix CVE-2011-2489, upgrade to the latest version of OPIE that has patched the off-by-one errors.
3
What types of systems are affected by CVE-2011-2489?
CVE-2011-2489 affects local users of OPIE versions 2.3 through 2.4.1-test1.
4
What kind of attack does CVE-2011-2489 facilitate?
CVE-2011-2489 allows local users to potentially escalate their privileges through crafted command lines.
5
Is CVE-2011-2489 still a risk for modern systems?
CVE-2011-2489 is less of a risk for modern systems if they are regularly updated to use the latest software versions.