CVE-2008-2230
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
11/06/2008
Last modified:
09/04/2025
Description
Untrusted search path vulnerability in (1) reportbug 3.8 and 3.31, and (2) reportbug-ng before 0.2008.06.04, allows local users to execute arbitrary code via a malicious module file in the current working directory.
Impact
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:reportbug-ng:reportbug:3.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug:3.31:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.10:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.11:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.13:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.14:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.15:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.17:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.19:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.19.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.20:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.24:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.27:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.28:*:*:*:*:*:*:* | ||
cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.29:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484311
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484474
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43001
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484311
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484474
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43001