Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-29906

Опубликовано: 29 апр. 2025
Источник: debian

Описание

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
finitfixed4.11-1package
finitignoredbookwormpackage

Примечания

  • https://github.com/troglobit/finit/security/advisories/GHSA-563g-p98j-mc9q

  • https://github.com/troglobit/finit/commit/6528628b5c771c25ffa0cb1a46c6c89d9d0d69e0 (4.11-rc1)

Связанные уязвимости

CVSS3: 8.6
ubuntu
9 месяцев назад

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.

CVSS3: 8.6
nvd
9 месяцев назад

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.

CVSS3: 8.6
fstec
11 месяцев назад

Уязвимость компонента getty системы инициализации finit, позволяющая нарушителю получить несанкционированный доступ к системе