Описание
In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.
Ссылки
- Third Party Advisory
- Third Party Advisory
- ExploitMailing ListThird Party Advisory
- Third Party Advisory
- ExploitMailing ListThird Party Advisory
- Vendor Advisory
- ExploitMailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- ExploitMailing ListThird Party Advisory
- Third Party Advisory
- ExploitMailing ListThird Party Advisory
- Vendor Advisory
- ExploitMailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:o:openbsd:openbsd:6.6:*:*:*:*:*:*:*
EPSS
Процентиль: 28%
0.00099
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
больше 3 лет назад
In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.
EPSS
Процентиль: 28%
0.00099
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-287