CVE-2013-4376
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
09/12/2013
Last modified:
11/04/2025
Description
The setgid wrapper libx2go-server-db-sqlite3-wrapper.c in X2Go Server before 4.0.0.2 allows remote attackers to execute arbitrary code via unspecified vectors, related to the path to libx2go-server-db-sqlite3-wrapper.pl.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:x2go:x2go_server:*:*:*:*:*:*:*:* | 4.0.0.1 (including) | |
cpe:2.3:a:x2go:x2go_server:4.0.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://code.x2go.org/gitweb?p=x2goserver.git%3Ba%3Dcommit%3Bh%3D42264c88d7885474ebe3763b2991681ddfcfa69a
- http://security.gentoo.org/glsa/glsa-201310-19.xml
- http://www.openwall.com/lists/oss-security/2013/09/25/11
- https://lists.berlios.de/pipermail/x2go-announcement/2013-May/000125.html
- http://code.x2go.org/gitweb?p=x2goserver.git%3Ba%3Dcommit%3Bh%3D42264c88d7885474ebe3763b2991681ddfcfa69a
- http://security.gentoo.org/glsa/glsa-201310-19.xml
- http://www.openwall.com/lists/oss-security/2013/09/25/11
- https://lists.berlios.de/pipermail/x2go-announcement/2013-May/000125.html