Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gm4g-p4jj-grph

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the old process port. This can be exploited to get full root access.

An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the old process port. This can be exploited to get full root access.

EPSS

Процентиль: 63%
0.00454
Низкий

7.5 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the old process port. This can be exploited to get full root access.

CVSS3: 7.5
debian
около 4 лет назад

An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying ...

EPSS

Процентиль: 63%
0.00454
Низкий

7.5 High

CVSS3

Дефекты

CWE-863