Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2p5v-37jh-xv37

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users.

Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users.

EPSS

Процентиль: 35%
0.00144
Низкий

Связанные уязвимости

nvd
больше 22 лет назад

Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users.

EPSS

Процентиль: 35%
0.00144
Низкий