Back

CVE-2006-0576

Untrusted search path vulnerability in opcontrol in OProfile 0.9.1 and earlier allows local users to execute arbitrary commands via a modified PATH that references malicious (1) which or (2) dirname programs. NOTE: while opcontrol normally is not run setuid, a common configuration suggests accessing opcontrol using sudo. In such a context, this is a vulnerability.

Published: Feb 8, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (18)

Vendor Product Version
maynard_johnson oprofile *
maynard_johnson oprofile 0.1
maynard_johnson oprofile 0.2
maynard_johnson oprofile 0.3
maynard_johnson oprofile 0.4
maynard_johnson oprofile 0.5
maynard_johnson oprofile 0.5.1
maynard_johnson oprofile 0.5.2
maynard_johnson oprofile 0.5.3
maynard_johnson oprofile 0.5.4
maynard_johnson oprofile 0.6
maynard_johnson oprofile 0.6.1
maynard_johnson oprofile 0.7
maynard_johnson oprofile 0.7.1
maynard_johnson oprofile 0.8
maynard_johnson oprofile 0.8.1
maynard_johnson oprofile 0.8.2
maynard_johnson oprofile 0.9

GitHub Security Advisory GHSA-9xvh-2qpv-m4fg

Untrusted search path vulnerability in opcontrol in OProfile 0.9.1 and earlier allows local users...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.40%

Top 68% most likely to be exploited

Threat Score 28.9 / 100

Data Sources

NVD EPSS GitHub