Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mcp-f38w-p5gf

Опубликовано: 12 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs.

The bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database.

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs.

The bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database.

EPSS

Процентиль: 48%
0.00249
Низкий

7.5 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs. The bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database.

EPSS

Процентиль: 48%
0.00249
Низкий

7.5 High

CVSS3

Дефекты

CWE-862