Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8m6j-c7jr-pc5f

Опубликовано: 29 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.

A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.

EPSS

Процентиль: 13%
0.00042
Низкий

8.4 High

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 8.4
redhat
почти 4 года назад

A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.

CVSS3: 8.4
nvd
больше 3 лет назад

A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.

CVSS3: 8.4
msrc
больше 3 лет назад

A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.

rocky
больше 3 лет назад

Moderate: fapolicyd security, bug fix, and enhancement update

oracle-oval
больше 3 лет назад

ELSA-2022-1898: fapolicyd security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 13%
0.00042
Низкий

8.4 High

CVSS3

Дефекты

CWE-552