Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m2cf-xghm-rxmc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.

OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.

EPSS

Процентиль: 73%
0.00786
Низкий

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 4.7
ubuntu
почти 6 лет назад

OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.

CVSS3: 4.7
nvd
почти 6 лет назад

OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.

CVSS3: 4.7
debian
почти 6 лет назад

OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g ...

EPSS

Процентиль: 73%
0.00786
Низкий

Дефекты

CWE-426