VulnerabilityModified
CVE-2005-0503
uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.
MEDIUM 4.6EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Affected
- uim/uim · mandrakesoft/mandrake linux
- Source
- cve@mitre.org
References
- http://lists.freedesktop.org/archives/uim/2005-February/000996.htmlVendor Advisory
- http://secunia.com/advisories/13981Patch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:046
- http://www.securityfocus.com/bid/12604Patch, Vendor Advisory
- http://lists.freedesktop.org/archives/uim/2005-February/000996.htmlVendor Advisory
- http://secunia.com/advisories/13981Patch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:046
- http://www.securityfocus.com/bid/12604Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.