CVE Vulnerabilities

CVE-2013-4984

Published: Sep 10, 2013 | Modified: Nov 08, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metacharacters in the second argument.

Affected Software

Name Vendor Start Version End Version
Web_appliance Sophos * 3.7.9 (including)
Web_appliance Sophos 3.0.0 (including) 3.0.0 (including)
Web_appliance Sophos 3.0.1 (including) 3.0.1 (including)
Web_appliance Sophos 3.0.1.1 (including) 3.0.1.1 (including)
Web_appliance Sophos 3.0.2 (including) 3.0.2 (including)
Web_appliance Sophos 3.0.3 (including) 3.0.3 (including)
Web_appliance Sophos 3.0.4 (including) 3.0.4 (including)
Web_appliance Sophos 3.0.5 (including) 3.0.5 (including)
Web_appliance Sophos 3.0.5.1 (including) 3.0.5.1 (including)
Web_appliance Sophos 3.1.0 (including) 3.1.0 (including)
Web_appliance Sophos 3.1.0.1 (including) 3.1.0.1 (including)
Web_appliance Sophos 3.1.1 (including) 3.1.1 (including)
Web_appliance Sophos 3.1.2 (including) 3.1.2 (including)
Web_appliance Sophos 3.1.3 (including) 3.1.3 (including)
Web_appliance Sophos 3.1.4 (including) 3.1.4 (including)
Web_appliance Sophos 3.2.1 (including) 3.2.1 (including)
Web_appliance Sophos 3.2.2 (including) 3.2.2 (including)
Web_appliance Sophos 3.2.2.1 (including) 3.2.2.1 (including)
Web_appliance Sophos 3.2.3 (including) 3.2.3 (including)
Web_appliance Sophos 3.2.4 (including) 3.2.4 (including)
Web_appliance Sophos 3.2.5 (including) 3.2.5 (including)
Web_appliance Sophos 3.2.6 (including) 3.2.6 (including)
Web_appliance Sophos 3.2.7 (including) 3.2.7 (including)
Web_appliance Sophos 3.3.0 (including) 3.3.0 (including)
Web_appliance Sophos 3.3.1 (including) 3.3.1 (including)
Web_appliance Sophos 3.3.2 (including) 3.3.2 (including)
Web_appliance Sophos 3.3.3 (including) 3.3.3 (including)
Web_appliance Sophos 3.3.3.1 (including) 3.3.3.1 (including)
Web_appliance Sophos 3.3.4 (including) 3.3.4 (including)
Web_appliance Sophos 3.3.5 (including) 3.3.5 (including)
Web_appliance Sophos 3.3.5.1 (including) 3.3.5.1 (including)
Web_appliance Sophos 3.3.6 (including) 3.3.6 (including)
Web_appliance Sophos 3.3.6.1 (including) 3.3.6.1 (including)
Web_appliance Sophos 3.4.0 (including) 3.4.0 (including)
Web_appliance Sophos 3.4.1 (including) 3.4.1 (including)
Web_appliance Sophos 3.4.2 (including) 3.4.2 (including)
Web_appliance Sophos 3.4.3 (including) 3.4.3 (including)
Web_appliance Sophos 3.4.3.1 (including) 3.4.3.1 (including)
Web_appliance Sophos 3.4.4 (including) 3.4.4 (including)
Web_appliance Sophos 3.4.5 (including) 3.4.5 (including)
Web_appliance Sophos 3.4.6 (including) 3.4.6 (including)
Web_appliance Sophos 3.4.7 (including) 3.4.7 (including)
Web_appliance Sophos 3.4.8 (including) 3.4.8 (including)
Web_appliance Sophos 3.5.0 (including) 3.5.0 (including)
Web_appliance Sophos 3.5.1 (including) 3.5.1 (including)
Web_appliance Sophos 3.5.1.1 (including) 3.5.1.1 (including)
Web_appliance Sophos 3.5.1.2 (including) 3.5.1.2 (including)
Web_appliance Sophos 3.5.2 (including) 3.5.2 (including)
Web_appliance Sophos 3.5.3 (including) 3.5.3 (including)
Web_appliance Sophos 3.5.4 (including) 3.5.4 (including)
Web_appliance Sophos 3.5.5 (including) 3.5.5 (including)
Web_appliance Sophos 3.5.6 (including) 3.5.6 (including)
Web_appliance Sophos 3.6.1 (including) 3.6.1 (including)
Web_appliance Sophos 3.6.1.1 (including) 3.6.1.1 (including)
Web_appliance Sophos 3.6.2 (including) 3.6.2 (including)
Web_appliance Sophos 3.6.2.1 (including) 3.6.2.1 (including)
Web_appliance Sophos 3.6.2.3 (including) 3.6.2.3 (including)
Web_appliance Sophos 3.6.2.4.0 (including) 3.6.2.4.0 (including)
Web_appliance Sophos 3.6.2.4.1 (including) 3.6.2.4.1 (including)
Web_appliance Sophos 3.6.3 (including) 3.6.3 (including)
Web_appliance Sophos 3.6.4 (including) 3.6.4 (including)
Web_appliance Sophos 3.6.4.1 (including) 3.6.4.1 (including)
Web_appliance Sophos 3.6.4.2 (including) 3.6.4.2 (including)
Web_appliance Sophos 3.7.0 (including) 3.7.0 (including)
Web_appliance Sophos 3.7.1 (including) 3.7.1 (including)
Web_appliance Sophos 3.7.2 (including) 3.7.2 (including)
Web_appliance Sophos 3.7.3 (including) 3.7.3 (including)
Web_appliance Sophos 3.7.4 (including) 3.7.4 (including)
Web_appliance Sophos 3.7.5 (including) 3.7.5 (including)
Web_appliance Sophos 3.7.6 (including) 3.7.6 (including)
Web_appliance Sophos 3.7.7 (including) 3.7.7 (including)
Web_appliance Sophos 3.7.8 (including) 3.7.8 (including)
Web_appliance Sophos 3.7.8.1 (including) 3.7.8.1 (including)
Web_appliance Sophos 3.7.8.2 (including) 3.7.8.2 (including)
Web_appliance Sophos 3.8.0 (including) 3.8.0 (including)
Web_appliance Sophos 3.8.1 (including) 3.8.1 (including)

References