Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-4089

EPSS 0.15% · P35
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-4089

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Ubuntu bzip2本地权限提升漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
bzip2是英国软件开发者Julian Seward所研发的一套用于类Unix操作系统中的开源文件压缩和解压工具。 bzip2 1.0.4及之前版本的bzexe命令中存在安全漏洞,该漏洞源于当生成压缩的可执行文件提取时,程序没有正确处理临时文件。本地攻击者可通过创建临时目录利用该漏洞执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-4089

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-4089

登录查看更多情报信息。

Same Patch Batch · n/a · 2014-04-16 · 97 CVEs total

CVE-2014-2463Oracle Secure Global Desktop 安全漏洞
CVE-2014-2459Oracle Transportation Management 任意代码执行漏洞
CVE-2014-2457Oracle Supply Chain Oracle Agile Product Lifecycle 安全漏洞
CVE-2014-2452Oracle Fusion Middleware Oracle Access Manager 拒绝服务漏洞
CVE-2014-2451Oracle MySQL Server 拒绝服务漏洞
CVE-2014-2450Oracle MySQL Server 拒绝服务漏洞
CVE-2014-2449Oracle PeopleSoft Enterprise HRMS Talent Acquisition Manager 安全漏洞
CVE-2014-2448Oracle PeopleSoft Enterprise PT PeopleTools 安全漏洞
CVE-2014-2453Oracle Hyperion 安全漏洞
CVE-2014-2461Oracle Transportation Management 安全漏洞
CVE-2014-2460Oracle Transportation Management 安全漏洞
CVE-2014-2464Oracle Agile PLM Framework 安全漏洞
CVE-2014-2465Oracle Agile PLM Framework 安全漏洞
CVE-2014-2466Oracle Agile PLM Framework 安全漏洞
CVE-2014-2467Oracle Agile PLM Framework 安全漏洞
CVE-2014-2468Oracle Siebel CRM 安全漏洞
CVE-2014-2470Oracle WebLogic Server 任意代码执行漏洞
CVE-2014-2471Oracle iLearning 安全漏洞
CVE-2014-0451Oracle Java SE和Java SE Embedded 安全漏洞
CVE-2014-0452Java SE和Java SE Embedded 安全漏洞

Showing top 20 of 97 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2011-4089

No comments yet


Leave a comment