Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-29906

Опубликовано: 29 апр. 2025
Источник: debian
EPSS Низкий

Описание

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
finitfixed4.11-1package
finitignoredbookwormpackage

Примечания

  • https://github.com/troglobit/finit/security/advisories/GHSA-563g-p98j-mc9q

  • https://github.com/troglobit/finit/commit/6528628b5c771c25ffa0cb1a46c6c89d9d0d69e0 (4.11-rc1)

EPSS

Процентиль: 12%
0.0022
Низкий

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 1 года назад

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.

CVSS3: 8.6
nvd
больше 1 года назад

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.

CVSS3: 8.6
fstec
больше 1 года назад

Уязвимость компонента getty системы инициализации finit, позволяющая нарушителю получить несанкционированный доступ к системе

EPSS

Процентиль: 12%
0.0022
Низкий
Уязвимость CVE-2025-29906