CVE-2013-2012 describes a local privilege escalation vulnerability in autojump versions prior to 21.5.8, affecting autojump_project and Debian Linux distributions. An attacker can exploit this by placing a malicious custom_install directory in the current working directory, tricking autojump into executing arbitrary code. With a CVSS score of 7.3 (HIGH), this vulnerability has a low attack complexity and requires user interaction, but can lead to high impact on confidentiality, integrity, and availability. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.5.8CPE matchmatch criteria | cpe:2.3:a:autojump_project:autojump:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.