CVE-2004-2611

UnknownEPSS 0.35%

Last modified

CVE-2004-2611 is a vulnerability of currently unknown severity. The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.

Description

The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities.

Metrics

EPSS Probability
0.35%

26.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Steven SchaeferSophster0.9.5_r8
Steven SchaeferSophster0.9.5_r10
Steven SchaeferSophster0.9.5_r12
Steven SchaeferSophster0.9.5_r15
Steven SchaeferSophster0.9.6_r1
Steven SchaeferSophster0.9.6_r2
Steven SchaeferSophster0.9.6_r3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2004-2611?
The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities.
How severe is CVE-2004-2611?
Severity scoring for CVE-2004-2611 is pending analysis. The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2004-2611?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2004-2611?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST