The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.
2004-10-20T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | debian | bsdmainutils | 6.0 | Yes |
Application | debian | bsdmainutils | 6.0.1 | Yes |
Application | debian | bsdmainutils | 6.0.2 | Yes |
Application | debian | bsdmainutils | 6.0.3 | Yes |
Application | debian | bsdmainutils | 6.0.4 | Yes |
Application | debian | bsdmainutils | 6.0.5 | Yes |
Application | debian | bsdmainutils | 6.0.6 | Yes |
Application | debian | bsdmainutils | 6.0.7 | Yes |
Application | debian | bsdmainutils | 6.0.8 | Yes |
Application | debian | bsdmainutils | 6.0.9 | Yes |
Application | debian | bsdmainutils | 6.0.10 | Yes |
Application | debian | bsdmainutils | 6.0.11 | Yes |
Application | debian | bsdmainutils | 6.0.12 | Yes |
Application | debian | bsdmainutils | 6.0.13 | Yes |
Application | debian | bsdmainutils | 6.0.14 | Yes |