CVE-2013-7172
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.46%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- slackware/slackware linux
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2013/12/20/1Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-7172Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89916Third Party Advisory, VDB Entry
- https://security-tracker.debian.org/tracker/CVE-2013-7172Third Party Advisory
- http://www.openwall.com/lists/oss-security/2013/12/20/1Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-7172Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89916Third Party Advisory, VDB Entry
- https://security-tracker.debian.org/tracker/CVE-2013-7172Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.