Описание
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.
Ссылки
- ExploitVendor Advisory
- PatchVendor Advisory
- ExploitVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:gnu:fingerd:1.37:*:*:*:*:*:*:*
EPSS
Процентиль: 15%
0.0005
Низкий
7.2 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
около 3 лет назад
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.
EPSS
Процентиль: 15%
0.0005
Низкий
7.2 High
CVSS2
Дефекты
NVD-CWE-Other