Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-11675

Опубликовано: 02 мая 2019
Источник: nvd
CVSS3: 7
CVSS2: 6.9
EPSS Низкий

Описание

The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root access because of unsafe interaction with logrotate. For example, an attacker can exploit a race condition to insert a symlink from /var/log/groonga/httpd to /etc/bash_completion.d. NOTE: this is an issue in the Debian packaging of the Groonga HTTP server.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:groonga:groonga-httpd:6.5.1-1:*:*:*:*:debian:*:*

EPSS

Процентиль: 9%
0.00033
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 7
ubuntu
почти 7 лет назад

The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root access because of unsafe interaction with logrotate. For example, an attacker can exploit a race condition to insert a symlink from /var/log/groonga/httpd to /etc/bash_completion.d. NOTE: this is an issue in the Debian packaging of the Groonga HTTP server.

CVSS3: 7
debian
почти 7 лет назад

The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ...

CVSS3: 7
github
больше 3 лет назад

The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root access because of unsafe interaction with logrotate. For example, an attacker can exploit a race condition to insert a symlink from /var/log/groonga/httpd to /etc/bash_completion.d. NOTE: this is an issue in the Debian packaging of the Groonga HTTP server.

EPSS

Процентиль: 9%
0.00033
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-362