Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.63563
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-732-1)
Summary:The remote host is missing an update for the 'dash' package(s) announced via the USN-732-1 advisory.
Description:Summary:
The remote host is missing an update for the 'dash' package(s) announced via the USN-732-1 advisory.

Vulnerability Insight:
Wolfgang M. Reimer discovered that dash, when invoked as a login shell, would
source .profile files from the current directory. Local users may be able to
bypass security restrictions and gain root privileges by placing specially
crafted .profile files where they might get sourced by other dash users.

Affected Software/OS:
'dash' package(s) on Ubuntu 8.04, Ubuntu 8.10.

Solution:
Please install the updated package(s).

CVSS Score:
6.9

CVSS Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-0854
BugTraq ID: 34092
http://www.securityfocus.com/bid/34092
http://secunia.com/advisories/34205
http://www.ubuntu.com/usn/USN-732-1
XForce ISS Database: dash-profile-code-execution(49216)
https://exchange.xforce.ibmcloud.com/vulnerabilities/49216
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.