Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7w8h-h4pj-jgjq

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escalation to delete arbitrary files.

An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escalation to delete arbitrary files.

EPSS

Процентиль: 9%
0.00031
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 5.3
nvd
больше 7 лет назад

An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escalation to delete arbitrary files.

EPSS

Процентиль: 9%
0.00031
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-367