// For flags

CVE-2009-0912

 

Severity Score

7.2
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

perl-MDK-Common 1.1.11 and 1.1.24, 1.2.9 through 1.2.14, and possibly other versions, in Mandriva Linux does not properly handle strings when writing them to configuration files, which allows attackers to gain privileges via "special characters" in unspecified vectors.

perl-MDK-Common v1.1.11 y v1.1.24, v1.2.9 hasta v1.2.14, y posiblemente otras versiones, en Mandriva Linux no maneja correctamente las cadenas de caracteres cuando las aƱade a ficheros de configuraciĆ³n, permitiendo a atacantes remotos obtener privilegios mediante "caracteres especiales" en vectores no especificados.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-03-16 CVE Reserved
  • 2009-03-16 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mandriva
Search vendor "Mandriva"
Multi Network Firewall
Search vendor "Mandriva" for product "Multi Network Firewall"
2.0
Search vendor "Mandriva" for product "Multi Network Firewall" and version "2.0"
-
Affected
Mandriva
Search vendor "Mandriva"
Linux
Search vendor "Mandriva" for product "Linux"
2008.0
Search vendor "Mandriva" for product "Linux" and version "2008.0"
-
Affected
Mandriva
Search vendor "Mandriva"
Linux
Search vendor "Mandriva" for product "Linux"
2008.0
Search vendor "Mandriva" for product "Linux" and version "2008.0"
x86_64
Affected
Mandriva
Search vendor "Mandriva"
Linux
Search vendor "Mandriva" for product "Linux"
2008.1
Search vendor "Mandriva" for product "Linux" and version "2008.1"
-
Affected
Mandriva
Search vendor "Mandriva"
Linux
Search vendor "Mandriva" for product "Linux"
2008.1
Search vendor "Mandriva" for product "Linux" and version "2008.1"
x86_64
Affected
Mandriva
Search vendor "Mandriva"
Linux
Search vendor "Mandriva" for product "Linux"
2009.0
Search vendor "Mandriva" for product "Linux" and version "2009.0"
-
Affected
Mandriva
Search vendor "Mandriva"
Linux
Search vendor "Mandriva" for product "Linux"
2009.0
Search vendor "Mandriva" for product "Linux" and version "2009.0"
x86_64
Affected
Mandriva
Search vendor "Mandriva"
Linux Corporate Server
Search vendor "Mandriva" for product "Linux Corporate Server"
3.0
Search vendor "Mandriva" for product "Linux Corporate Server" and version "3.0"
-
Affected
Mandriva
Search vendor "Mandriva"
Linux Corporate Server
Search vendor "Mandriva" for product "Linux Corporate Server"
3.0
Search vendor "Mandriva" for product "Linux Corporate Server" and version "3.0"
x86_64
Affected
Mandriva
Search vendor "Mandriva"
Linux Corporate Server
Search vendor "Mandriva" for product "Linux Corporate Server"
4.0
Search vendor "Mandriva" for product "Linux Corporate Server" and version "4.0"
-
Affected
Mandriva
Search vendor "Mandriva"
Linux Corporate Server
Search vendor "Mandriva" for product "Linux Corporate Server"
4.0
Search vendor "Mandriva" for product "Linux Corporate Server" and version "4.0"
x86_64
Affected