CVE-2008-2359

high

Description

The default configuration of consolehelper in system-config-network before 1.5.10-1 on Fedora 8 lacks the USER=root directive, which allows local users of the workstation console to gain privileges and change the network configuration.

References

https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00974.html

https://exchange.xforce.ibmcloud.com/vulnerabilities/42867

https://bugzilla.redhat.com/show_bug.cgi?id=448557

http://secunia.com/advisories/30399

Details

Source: Mitre, NVD

Published: 2008-06-02

Updated: 2017-08-08

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High