Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q9g5-vjrr-pw76

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.

libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.

EPSS

Процентиль: 36%
0.0044
Низкий

Связанные уязвимости

ubuntu
около 14 лет назад

libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.

redhat
около 15 лет назад

libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.

nvd
около 14 лет назад

libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.

debian
около 14 лет назад

libgssapi and libgssglue before 0.4 do not properly check privileges, ...

fstec
почти 14 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 36%
0.0044
Низкий