Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-3589

Опубликовано: 08 окт. 2009
Источник: nvd
CVSS2: 4.6
EPSS Низкий

Описание

incron 0.5.5 does not initialize supplementary groups when running a process from a user's incrontabs, which causes the process to be run with the incrond supplementary groups and allows local users to gain privileges via an incrontab table.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:inotify:incron:0.5.5:*:*:*:*:*:*:*

EPSS

Процентиль: 16%
0.00052
Низкий

4.6 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
около 16 лет назад

incron 0.5.5 does not initialize supplementary groups when running a process from a user's incrontabs, which causes the process to be run with the incrond supplementary groups and allows local users to gain privileges via an incrontab table.

debian
около 16 лет назад

incron 0.5.5 does not initialize supplementary groups when running a p ...

github
больше 3 лет назад

incron 0.5.5 does not initialize supplementary groups when running a process from a user's incrontabs, which causes the process to be run with the incrond supplementary groups and allows local users to gain privileges via an incrontab table.

EPSS

Процентиль: 16%
0.00052
Низкий

4.6 Medium

CVSS2

Дефекты

CWE-264