« Volver al listado

CVE-2008-1056

Estado: ModificadaMedia (6.9)—

Multiple stack-based buffer overflows in Symark PowerBroker 2.8 through 5.0.1 allow local users to gain privileges via a long argv[0] string when executing (1) pbrun, (2) pbsh, or (3) pbksh. NOTE: the product is often installed in environments with trust relationships that facilitate subsequent remote compromises.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-1056",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-02-28T19:44:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/29111",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mnin.org/advisories/2008_symarkpb.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/28015",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.symark.com/support/PBFeb2008Announcement.html",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40872",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/29111",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mnin.org/advisories/2008_symarkpb.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/28015",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.symark.com/support/PBFeb2008Announcement.html",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40872",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple stack-based buffer overflows in Symark PowerBroker 2.8 through 5.0.1 allow local users to gain privileges via a long argv[0] string when executing (1) pbrun, (2) pbsh, or (3) pbksh.  NOTE: the product is often installed in environments with trust relationships that facilitate subsequent remote compromises."
    },
    {
      "lang": "es",
      "value": "Múltiples desbordamientos de búfer basados en pila en Symark PowerBroker de 2.8 a 5.0.1 permiten a usuarios locales obtener privilegios a través de una cadena argv[0] larga cuando se ejecuta 1) pbrun, (2) pbsh, o (3) pbksh. NOTA: el producto a veces se instala en entornos con relaciones de confianza que facilitan compromisos de subsecuencia remota."
    }
  ],
  "lastModified": "2026-06-16T22:50:53.600",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:symark:powerbroker:2.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F16E3B69-F425-4FAB-9201-2CF0590016B5"
            },
            {
              "criteria": "cpe:2.3:a:symark:powerbroker:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16AB3CBC-A6A6-487D-A530-9E45B4BFDD9D"
            },
            {
              "criteria": "cpe:2.3:a:symark:powerbroker:3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD7ADE8D-CC82-4BB7-9BA1-90DCBE7DFC0A"
            },
            {
              "criteria": "cpe:2.3:a:symark:powerbroker:3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47E587CF-6F19-4BB1-8C30-577D4F1D6DEF"
            },
            {
              "criteria": "cpe:2.3:a:symark:powerbroker:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B255DD3-556A-4B77-8479-062E841EED10"
            },
            {
              "criteria": "cpe:2.3:a:symark:powerbroker:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0131FCF9-69F4-46DA-8A6B-81FB722170BF"
            },
            {
              "criteria": "cpe:2.3:a:symark:powerbroker:5.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D8BED834-E613-423A-82F7-A2E0FF158641"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}