Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mgmg-j29c-p5ff

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.

GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.

EPSS

Процентиль: 15%
0.0005
Низкий

Связанные уязвимости

nvd
почти 26 лет назад

GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.

EPSS

Процентиль: 15%
0.0005
Низкий