Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-2781

Опубликовано: 07 фев. 2017
Источник: debian
EPSS Низкий

Описание

chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
coreutilsfixed9.4-1package
coreutilsignoredbookwormpackage
coreutilsignoredbullseyepackage
coreutilsignoredbusterpackage
coreutilsignoredstretchpackage
coreutilsignoredjessiepackage
coreutilsignoredwheezypackage

Примечания

  • Restricting ioctl on the kernel side seems the better approach, but rejected by Linux upstream

  • Fixing this issue via setsid() would introduce regressions:

  • https://www.kernel.org/pub/linux/utils/util-linux/v2.28/v2.28-ReleaseNotes

  • Since Linux 6.4.4-1 (uploaded on 23 Jul 2023), TIOCSTI is disabled on the

  • kernel side, marking the first coreutils upload after that date (9.4-1) as the

  • fixed version

EPSS

Процентиль: 26%
0.00086
Низкий

Связанные уязвимости

CVSS3: 4.6
ubuntu
больше 8 лет назад

chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

CVSS3: 8.6
redhat
больше 9 лет назад

chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

CVSS3: 4.6
nvd
больше 8 лет назад

chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

CVSS3: 4.6
msrc
9 дней назад

Описание отсутствует

CVSS3: 6.5
github
около 3 лет назад

chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

EPSS

Процентиль: 26%
0.00086
Низкий