VulnerabilityModified
CVE-2005-3546
suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.
HIGH 7.2EPSS 0.80%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.80% probability · 55th percentile
- CISA KEV
- Not listed
- Affected
- f-secure/f-secure anti-virus · f-secure/internet gatekeeper
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/17467Patch, Vendor Advisory
- http://securitytracker.com/id?1015159
- http://securitytracker.com/id?1015160
- http://www.f-secure.com/security/fsc-2005-3.shtmlPatch, Vendor Advisory
- http://www.osvdb.org/20513
- http://www.osvdb.org/20537
- http://www.osvdb.org/20538
- http://www.osvdb.org/20539
- http://www.osvdb.org/20540
- http://www.osvdb.org/20541
- http://www.osvdb.org/20542
- http://www.osvdb.org/20543
- http://www.osvdb.org/20544
- http://www.osvdb.org/20545
- http://www.osvdb.org/20546
- http://www.osvdb.org/20547
- http://www.osvdb.org/20548
- http://www.osvdb.org/20549
- http://www.osvdb.org/20550
- http://www.osvdb.org/20551
- http://www.osvdb.org/20552
- http://www.securityfocus.com/bid/15339
- http://www.vupen.com/english/advisories/2005/2331
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22966
- http://secunia.com/advisories/17467Patch, Vendor Advisory
- http://securitytracker.com/id?1015159
- http://securitytracker.com/id?1015160
- http://www.f-secure.com/security/fsc-2005-3.shtmlPatch, Vendor Advisory
- http://www.osvdb.org/20513
- http://www.osvdb.org/20537
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.