Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4532-mwp5-jccg

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.

artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.

EPSS

Процентиль: 35%
0.00145
Низкий

7.8 High

CVSS3

Дефекты

CWE-273

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 19 лет назад

artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.

CVSS3: 6.7
redhat
больше 1 года назад

artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.

CVSS3: 7.8
nvd
около 19 лет назад

artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.

CVSS3: 7.8
debian
около 19 лет назад

artswrapper in aRts, when running setuid root on Linux 2.6.0 or later ...

fstec
около 19 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 35%
0.00145
Низкий

7.8 High

CVSS3

Дефекты

CWE-273