The CGIwrap program before 3.9 on Debian GNU/Linux uses an incorrect minimum value of 100 for a UID to determine whether it can perform a seteuid operation, which could allow attackers to execute code as other system UIDs that are greater than the minimum value, which should be 1000 on Debian systems.
2005-10-18T21:02:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nathan_neulinger | cgiwrap | 1.0 | Yes |
Application | nathan_neulinger | cgiwrap | 2.0 | Yes |
Application | nathan_neulinger | cgiwrap | 2.1 | Yes |
Application | nathan_neulinger | cgiwrap | 2.2 | Yes |
Application | nathan_neulinger | cgiwrap | 2.3 | Yes |
Application | nathan_neulinger | cgiwrap | 2.4 | Yes |
Application | nathan_neulinger | cgiwrap | 2.5 | Yes |
Application | nathan_neulinger | cgiwrap | 2.6 | Yes |
Application | nathan_neulinger | cgiwrap | 2.7 | Yes |
Application | nathan_neulinger | cgiwrap | 3.0 | Yes |
Application | nathan_neulinger | cgiwrap | 3.1 | Yes |
Application | nathan_neulinger | cgiwrap | 3.2 | Yes |
Application | nathan_neulinger | cgiwrap | 3.3 | Yes |
Application | nathan_neulinger | cgiwrap | 3.4 | Yes |
Application | nathan_neulinger | cgiwrap | 3.5 | Yes |
Application | nathan_neulinger | cgiwrap | 3.6 | Yes |
Application | nathan_neulinger | cgiwrap | 3.6.1 | Yes |
Application | nathan_neulinger | cgiwrap | 3.6.2 | Yes |
Application | nathan_neulinger | cgiwrap | 3.6.3 | Yes |
Application | nathan_neulinger | cgiwrap | 3.6.4 | Yes |
Application | nathan_neulinger | cgiwrap | 3.6.5 | Yes |
Application | nathan_neulinger | cgiwrap | 3.7 | Yes |
Application | nathan_neulinger | cgiwrap | 3.7.1 | Yes |
Application | nathan_neulinger | cgiwrap | 3.8 | Yes |
Application | nathan_neulinger | cgiwrap | 3.11 | Yes |
Application | nathan_neulinger | cgiwrap | 3.21 | Yes |
Application | nathan_neulinger | cgiwrap | 3.22 | Yes |
Application | nathan_neulinger | cgiwrap | 3.23 | Yes |
Application | nathan_neulinger | cgiwrap | 3.24 | Yes |