Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8qrg-f3r4-2pv6

Опубликовано: 21 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck user because of insecure recursive chown calls.

In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck user because of insecure recursive chown calls.

EPSS

Процентиль: 54%
0.00309
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck user because of insecure recursive chown calls.

CVSS3: 9.8
nvd
больше 3 лет назад

In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck user because of insecure recursive chown calls.

EPSS

Процентиль: 54%
0.00309
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-732