Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hvr4-2p3v-j73r

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.

cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.

EPSS

Процентиль: 21%
0.00066
Низкий

Связанные уязвимости

nvd
около 24 лет назад

cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.

EPSS

Процентиль: 21%
0.00066
Низкий