CVE-2013-7172
Last modified
CVE-2013-7172 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Slackware | Slackware Linux | 13.1 |
| Slackware | Slackware Linux | 13.37 |
| Slackware | Slackware Linux | 14.0 |
| Slackware | Slackware Linux | 14.1 |
References
- https://www.openwall.com/lists/oss-security/2013/12/20/1Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-7172Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89916Third Party Advisory, VDB Entry
- https://security-tracker.debian.org/tracker/CVE-2013-7172Third Party Advisory
- https://www.openwall.com/lists/oss-security/2013/12/20/1Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-7172Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89916Third Party Advisory, VDB Entry
- https://security-tracker.debian.org/tracker/CVE-2013-7172Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-7172?
How severe is CVE-2013-7172?
How do I fix CVE-2013-7172?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-7165Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-7166Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-7167Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-7168Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-7169Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-7171Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3…9.8
- CVE-2013-7173Belkin n750 routers have a buffer overflow.9.8
- CVE-2013-7174Absolute path traversal vulnerability in cgi-bin/jc.cgi in Q…
- CVE-2013-7175Multiple SQL injection vulnerabilities in Avanset Visual Cer…
- CVE-2013-7176config/filter.d/postfix.conf in the postfix filter in Fail2b…
- CVE-2013-7177config/filter.d/cyrus-imap.conf in the cyrus-imap filter in …
- CVE-2013-7179The ping functionality in cgi-bin/diagnostic.cgi on Seowon I…
Are you affected by CVE-2013-7172?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
