Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rc87-8mcw-q34j

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.

libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.

EPSS

Процентиль: 33%
0.00129
Низкий

Связанные уязвимости

nvd
почти 24 года назад

libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.

EPSS

Процентиль: 33%
0.00129
Низкий