CVE-2011-1946
Estado: ModificadaAlta (7.2)—
gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid function, which allows local users to gain privileges by leveraging access to two unprivileged user accounts, and running many processes under one of these accounts.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.36%
- Percentil entre todas las CVEs puntuadas: 27
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://openwall.com/lists/oss-security/2011/05/30/2
- http://openwall.com/lists/oss-security/2011/05/31/11
- http://www.securityfocus.com/bid/48035
- https://bugzilla.novell.com/show_bug.cgi?id=695627
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67720
- http://openwall.com/lists/oss-security/2011/05/30/2
- http://openwall.com/lists/oss-security/2011/05/31/11
- http://www.securityfocus.com/bid/48035
- https://bugzilla.novell.com/show_bug.cgi?id=695627
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67720
JSON original (NVD)
Mostrar
{
"id": "CVE-2011-1946",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-07-07T21:55:02.133",
"references": [
{
"url": "http://openwall.com/lists/oss-security/2011/05/30/2",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://openwall.com/lists/oss-security/2011/05/31/11",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/48035",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.novell.com/show_bug.cgi?id=695627",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67720",
"source": "secalert@redhat.com"
},
{
"url": "http://openwall.com/lists/oss-security/2011/05/30/2",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://openwall.com/lists/oss-security/2011/05/31/11",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/48035",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.novell.com/show_bug.cgi?id=695627",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67720",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid function, which allows local users to gain privileges by leveraging access to two unprivileged user accounts, and running many processes under one of these accounts."
},
{
"lang": "es",
"value": "gnomesu-pam-backend en libgnomesu v1.0.0 muestra un mensaje de error pero continúa con la ejecución normal en caso de fallo de la función setuid o setgid, lo que permite a usuarios locales conseguir privilegios, aprovechando el acceso a dos cuentas de usuario sin privilegios, y ejecutando muchos procesos en una de estas cuentas."
}
],
"lastModified": "2026-06-16T23:30:26.727",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hongli_lai:libgnomesu:1.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "32364E8A-2810-492A-9008-6EEA80D02ED9"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}