Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-23301

Опубликовано: 12 янв. 2024
Источник: debian
EPSS Низкий

Описание

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rearfixed2.7+dfsg-1.2package
rearfixed2.7+dfsg-1+deb12u1bookwormpackage

Примечания

  • https://github.com/rear/rear/issues/3122

  • https://github.com/rear/rear/pull/3123

  • https://github.com/rear/rear/commit/89b61793d80bc2cb2abe47a7d0549466fb087d16

EPSS

Процентиль: 25%
0.00084
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 лет назад

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.

CVSS3: 5.5
redhat
около 2 лет назад

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.

CVSS3: 5.5
nvd
около 2 лет назад

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.

suse-cvrf
почти 2 года назад

Security update for rear27a

suse-cvrf
почти 2 года назад

Security update for rear1172a

EPSS

Процентиль: 25%
0.00084
Низкий