CVE-2008-2359
Severity CVSS v4.0:
Pending analysis
Type:
CWE-16
Configuration Errors
Publication date:
02/06/2008
Last modified:
09/04/2025
Description
The default configuration of consolehelper in system-config-network before 1.5.10-1 on Fedora 8 lacks the USER=root directive, which allows local users of the workstation console to gain privileges and change the network configuration.
Impact
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:fedora_8:consolehelper:1.4.4:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.4.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.4.6:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.4.7:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.5.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.5.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.5.3:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.5.4:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.5.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.5.6:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.5.7:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.5.8:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.5.9:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedora_8:consolehelper:1.5.10:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/30399
- https://bugzilla.redhat.com/show_bug.cgi?id=448557
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42867
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00974.html
- http://secunia.com/advisories/30399
- https://bugzilla.redhat.com/show_bug.cgi?id=448557
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42867
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00974.html



