Описание
Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.
Ссылки
- PatchThird Party AdvisoryUS Government Resource
- PatchVendor Advisory
- PatchThird Party AdvisoryUS Government Resource
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:joerg_schilling:star_tape_archiver:1.5_a45:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00066
Низкий
7.2 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
debian
почти 21 год назад
Star before 1.5_alpha46 does not drop the effective user ID (euid) bef ...
github
больше 3 лет назад
Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.
EPSS
Процентиль: 21%
0.00066
Низкий
7.2 High
CVSS2
Дефекты
NVD-CWE-Other