CVE-2011-2921
Summary
| CVE | CVE-2011-2921 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-19 17:15:00 UTC |
| Updated | 2019-11-21 18:55:00 UTC |
| Description | ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges. |
Risk And Classification
Problem Types: CWE-273
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ktsuss Project | Ktsuss | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2011-2921 | MISC | security-tracker.debian.org | Third Party Advisory |
| Red Hat Customer Portal | MISC | access.redhat.com | Broken Link, Third Party Advisory |
| ktsuss Suid Privilege Escalation ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.