Back to search
CVE-2009-4607
Published: Jan 13, 2010
Modified: Aug 7, 2024
PUBLISHED
Description
The command line interface in Overland Storage Snap Server 410 with GuardianOS 5.1.041 runs the "less" utility with a higher-privileged uid than the CLI user and without sufficient restriction on shell escapes, which allows local users to gain privileges using the "!" character within less to access a privileged shell.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
36739
vdb-entry
x_refsource_BID
snapserver-less-priv-escalation(53881)
vdb-entry
x_refsource_XF
20091020 Overland Guardian OS CLI command line bug - let you get uid 0 shell
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now