Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-10151

Опубликовано: 01 мар. 2017
Источник: nvd
CVSS3: 7
CVSS2: 6.9
EPSS Низкий

Описание

The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID with UID to determine whether to use configurations from environment variables, which allows local users to gain privileges via the (1) HESIOD_CONFIG or (2) HES_DOMAIN environment variable and leveraging certain SUID/SGUID binary.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hesiod_project:hesiod:3.2.1:*:*:*:*:*:*:*

EPSS

Процентиль: 31%
0.00116
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

CVSS3: 7
ubuntu
почти 9 лет назад

The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID with UID to determine whether to use configurations from environment variables, which allows local users to gain privileges via the (1) HESIOD_CONFIG or (2) HES_DOMAIN environment variable and leveraging certain SUID/SGUID binary.

CVSS3: 7
redhat
почти 10 лет назад

The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID with UID to determine whether to use configurations from environment variables, which allows local users to gain privileges via the (1) HESIOD_CONFIG or (2) HES_DOMAIN environment variable and leveraging certain SUID/SGUID binary.

CVSS3: 7
debian
почти 9 лет назад

The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID ...

CVSS3: 7
github
больше 3 лет назад

The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID with UID to determine whether to use configurations from environment variables, which allows local users to gain privileges via the (1) HESIOD_CONFIG or (2) HES_DOMAIN environment variable and leveraging certain SUID/SGUID binary.

EPSS

Процентиль: 31%
0.00116
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-264