Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-4415

Опубликовано: 11 янв. 2023
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
systemdfixed252.4-1package
systemdfixed247.3-7+deb11u2bullseyepackage
systemdignoredbusterpackage

Примечания

  • Preparation (main branch commit only): https://github.com/systemd/systemd/commit/510a146634f3e095b34e2a26023b1b1f99dcb8c0

  • Fixed by: https://github.com/systemd/systemd/commit/3e4d0f6cf99f8677edd6a237382a65bfe758de03

  • Fixed by: https://github.com/systemd/systemd-stable/commit/bb47600aeb38c68c857fbf0ee5f66c3144dd81ce (v247.13)

  • Affects only v246 and newer (when acl support was enabled by default), and only if building with libacl support

  • Optional (disabled by default) faulty behaviour introduced by v215

  • https://www.openwall.com/lists/oss-security/2022/12/21/3

EPSS

Процентиль: 4%
0.00023
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.

CVSS3: 5.5
redhat
больше 2 лет назад

A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.

CVSS3: 5.5
nvd
больше 2 лет назад

A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.

CVSS3: 5.5
msrc
больше 2 лет назад

Описание отсутствует

suse-cvrf
больше 2 лет назад

Security update for systemd

EPSS

Процентиль: 4%
0.00023
Низкий