« Volver al listado

CVE-2004-2611

Estado: ModificadaMedia (4.6)—

The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2004-2611",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": true,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2004-12-31T05:00:00.000",
  "references": [
    {
      "url": "http://securitytracker.com/id?1010431",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/6657",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.schaefer.dhcp.biz/CHANGELOG.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16359",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1010431",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/6657",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.schaefer.dhcp.biz/CHANGELOG.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16359",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities."
    }
  ],
  "lastModified": "2026-06-16T22:09:58.800",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:steven_schaefer:sophster:0.9.5_r8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1184CE98-CB70-4074-98A0-DD0E695C12D2"
            },
            {
              "criteria": "cpe:2.3:a:steven_schaefer:sophster:0.9.5_r10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6194DC91-3060-4749-9B54-C5E3A8D77B73"
            },
            {
              "criteria": "cpe:2.3:a:steven_schaefer:sophster:0.9.5_r12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A268501A-275C-4567-9A86-507E6D513E53"
            },
            {
              "criteria": "cpe:2.3:a:steven_schaefer:sophster:0.9.5_r15:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2460BD82-EF71-4331-827A-4DB9CE2B1F6D"
            },
            {
              "criteria": "cpe:2.3:a:steven_schaefer:sophster:0.9.6_r1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D8BF740A-C0FB-46E1-9B05-3FAF48A8F43F"
            },
            {
              "criteria": "cpe:2.3:a:steven_schaefer:sophster:0.9.6_r2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F971CDEE-95DF-4DB1-99D9-008421897BEF"
            },
            {
              "criteria": "cpe:2.3:a:steven_schaefer:sophster:0.9.6_r3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3FDCF8B-7A34-4ADF-9B46-4E31126E89C5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}