Описание
sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.
Ссылки
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:o:debian:debian_linux:2.2:*:*:*:*:*:*:*
EPSS
Процентиль: 24%
0.00083
Низкий
7.8 High
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-281
Связанные уязвимости
CVSS3: 7.8
github
почти 4 года назад
sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.
EPSS
Процентиль: 24%
0.00083
Низкий
7.8 High
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-281