CVE-2011-4338
Summary
| CVE | CVE-2011-4338 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-12 19:15:00 UTC |
| Updated | 2020-02-25 18:54:00 UTC |
| Description | Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in shaman. The next time shaman is run, root privileges are granted despite the fact that the user never entered the root password. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Shaman Project | Shaman | 1.0.9 | All | All | All |
| Application | Shaman Project | Shaman | 1.0.9 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Shaman doesn't ask for root password. But gets root privileges!! (Page 1) / Pacman & Package Upgrade Issues / Arch Linux Forums | MISC | bbs.archlinux.org | Exploit, Third Party Advisory |
| oss-security - Re: Did this ArchLinux/shaman thing ever get a CVE? | MISC | www.openwall.com | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.