Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8hvh-7pr8-r6wh

Опубликовано: 21 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileges. There is a race condition involving /var/lib/smokeping and chown.

In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileges. There is a race condition involving /var/lib/smokeping and chown.

EPSS

Процентиль: 53%
0.00302
Низкий

7.5 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileges. There is a race condition involving /var/lib/smokeping and chown.

CVSS3: 7.5
nvd
больше 3 лет назад

In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileges. There is a race condition involving /var/lib/smokeping and chown.

EPSS

Процентиль: 53%
0.00302
Низкий

7.5 High

CVSS3

Дефекты

CWE-362