Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5pgj-xv2m-m63j

Опубликовано: 03 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.

The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.

EPSS

Процентиль: 19%
0.0006
Низкий

Связанные уязвимости

nvd
около 24 лет назад

The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.

EPSS

Процентиль: 19%
0.0006
Низкий