CVE-2009-0667

Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
ocsinventory-ngocs_inventory_ng
1.0
ocsinventory-ngocs_inventory_ng
1.0:beta
ocsinventory-ngocs_inventory_ng
1.0:rc1
ocsinventory-ngocs_inventory_ng
1.0:rc2
ocsinventory-ngocs_inventory_ng
1.0:rc3
ocsinventory-ngocs_inventory_ng
1.0:rc3-1
ocsinventory-ngocsinventory-agent
𝑥
≤ 0.0.9.2
ocsinventory-ngocsinventory-agent
0.05
ocsinventory-ngocsinventory-agent
0.08
ocsinventory-ngocsinventory-agent
0.09
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ocsinventory-agent
bullseye
2:2.8-1
fixed
bookworm
2:2.10.0-3
fixed
sid
2:2.10.0-4
fixed
trixie
2:2.10.0-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ocsinventory-agent
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
ignored
intrepid
ignored
hardy
ignored
dapper
dne