CVE-2005-1307
The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 3.65% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- adobe/version cue · apple/mac os x
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2004-12/0040.html
- http://marc.info/?l=bugtraq&m=111627622403544&w=2
- http://secunia.com/advisories/13399
- http://securitytracker.com/id?1012446
- http://www.adobe.com/support/techdocs/331621.html
- http://www.osvdb.org/12297
- http://www.osvdb.org/12298
- http://www.securiteam.com/exploits/5EP0D20FQC.htmlExploit
- http://www.securityfocus.com/bid/11833
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18445
- http://archives.neohapsis.com/archives/bugtraq/2004-12/0040.html
- http://marc.info/?l=bugtraq&m=111627622403544&w=2
- http://secunia.com/advisories/13399
- http://securitytracker.com/id?1012446
- http://www.adobe.com/support/techdocs/331621.html
- http://www.osvdb.org/12297
- http://www.osvdb.org/12298
- http://www.securiteam.com/exploits/5EP0D20FQC.htmlExploit
- http://www.securityfocus.com/bid/11833
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18445
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.