Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-23301

Опубликовано: 12 янв. 2024
Источник: debian
EPSS Низкий

Описание

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rearfixed2.7+dfsg-1.2package
rearno-dsabookwormpackage
rearno-dsabullseyepackage

Примечания

  • https://github.com/rear/rear/issues/3122

  • https://github.com/rear/rear/pull/3123

  • https://github.com/rear/rear/commit/89b61793d80bc2cb2abe47a7d0549466fb087d16

EPSS

Процентиль: 31%
0.00112
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 1 года назад

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.

CVSS3: 5.5
redhat
больше 1 года назад

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.

CVSS3: 5.5
nvd
больше 1 года назад

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.

suse-cvrf
больше 1 года назад

Security update for rear27a

suse-cvrf
больше 1 года назад

Security update for rear1172a

EPSS

Процентиль: 31%
0.00112
Низкий