CVE-2011-0523
Estado: ModificadaBaja (1.9)—
gypsy 0.8 does not properly restrict the files that can be read while running with root privileges, which allows local users to read otherwise restricted files via unspecified vectors.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N
- Puntuación base: 1.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.48%
- Percentil entre todas las CVEs puntuadas: 39
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://cgit.freedesktop.org/gypsy/commit/?id=40101707cddb319481133b2a137294b6b669bd16
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106919.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106927.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107020.html
- http://lists.opensuse.org/opensuse-updates/2012-07/msg00034.html
- http://secunia.com/advisories/49991
- http://www.openwall.com/lists/oss-security/2011/01/24/10
- http://www.openwall.com/lists/oss-security/2011/01/25/10
- https://bugs.freedesktop.org/show_bug.cgi?id=33431
- https://bugs.launchpad.net/ubuntu/+source/gypsy/+bug/690323
- http://cgit.freedesktop.org/gypsy/commit/?id=40101707cddb319481133b2a137294b6b669bd16
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106919.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106927.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107020.html
- http://lists.opensuse.org/opensuse-updates/2012-07/msg00034.html
- http://secunia.com/advisories/49991
- http://www.openwall.com/lists/oss-security/2011/01/24/10
- http://www.openwall.com/lists/oss-security/2011/01/25/10
- https://bugs.freedesktop.org/show_bug.cgi?id=33431
- https://bugs.launchpad.net/ubuntu/+source/gypsy/+bug/690323
JSON original (NVD)
Mostrar
{
"id": "CVE-2011-0523",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 1.9,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-08-13T20:55:01.647",
"references": [
{
"url": "http://cgit.freedesktop.org/gypsy/commit/?id=40101707cddb319481133b2a137294b6b669bd16",
"tags": [
"Exploit",
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106919.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106927.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107020.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2012-07/msg00034.html",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/49991",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2011/01/24/10",
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2011/01/25/10",
"source": "secalert@redhat.com"
},
{
"url": "https://bugs.freedesktop.org/show_bug.cgi?id=33431",
"source": "secalert@redhat.com"
},
{
"url": "https://bugs.launchpad.net/ubuntu/+source/gypsy/+bug/690323",
"source": "secalert@redhat.com"
},
{
"url": "http://cgit.freedesktop.org/gypsy/commit/?id=40101707cddb319481133b2a137294b6b669bd16",
"tags": [
"Exploit",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106919.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106927.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107020.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2012-07/msg00034.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/49991",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2011/01/24/10",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2011/01/25/10",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.freedesktop.org/show_bug.cgi?id=33431",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.launchpad.net/ubuntu/+source/gypsy/+bug/690323",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "gypsy 0.8 does not properly restrict the files that can be read while running with root privileges, which allows local users to read otherwise restricted files via unspecified vectors."
},
{
"lang": "es",
"value": "gypsy v0.8 no restringe adecuadamente los archivos que se pueden leer cuando se ejecuta con privilegios de superadministrador, lo que permite a usuarios locales leer algunos ficheros restringidos a través de vectores no especificados.\r\n"
}
],
"lastModified": "2026-06-16T23:27:33.517",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:iain:gypsy:0.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24D0541B-DE92-4B8D-AEB6-488E86B10128"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}