CVE-2011-4954: High severity cobbler vulnerability
Published Nov 19, 2019
·Updated
cobbler has local privilege escalation via the use of insecure location for PYTHONEGGCACHE
Affected Software
2 affected components
debian/cobbler
Cobblerd Cobbler
Event History
Nov 19, 2019
CVE Published
via MITRE·03:41 PM
Data Sourced
via MITRE·03:41 PM
DescriptionWeakness
Aug 7, 2024
Data Sourced
via Debian·12:31 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4954?
CVE-2011-4954 has been classified as a moderate severity vulnerability due to the potential for local privilege escalation.
2
How do I fix CVE-2011-4954?
To fix CVE-2011-4954, ensure that the PYTHON_EGG_CACHE directory is secured and not writable by unprivileged users.
3
What systems are affected by CVE-2011-4954?
CVE-2011-4954 affects Cobbler and related systems that utilize the insecure PYTHON_EGG_CACHE location.
4
What kind of attack does CVE-2011-4954 enable?
CVE-2011-4954 enables local privilege escalation, allowing a low-privileged user to gain elevated permissions.
5
Is CVE-2011-4954 a remote or local vulnerability?
CVE-2011-4954 is a local vulnerability, requiring access to the system to exploit.