Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-44038

Опубликовано: 19 нояб. 2021
Источник: debian

Описание

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
quaggaremovedpackage
quaggano-dsabusterpackage
quaggapostponedstretchpackage

Примечания

  • https://bugzilla.suse.com/show_bug.cgi?id=1191890

  • Debian installed systemd unit files install the problematic redhat/*.service

  • files with the unsafe chmod/chown calls in the Debian packaging.

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 4 лет назад

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

CVSS3: 7.3
redhat
около 4 лет назад

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

CVSS3: 7.8
nvd
около 4 лет назад

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

CVSS3: 7.8
msrc
4 месяца назад

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

CVSS3: 7.8
github
около 4 лет назад

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.