Описание
GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary files because it handles configuration-file errors by printing the configuration file while executing in a setuid root context.
Ссылки
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Vendor Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.9.18 (включая)Версия до 2.1.17 (исключая)
Одновременно
cpe:2.3:a:gns3:ubridge:*:*:*:*:*:macos:*:*
cpe:2.3:a:gns3:gns3:*:*:*:*:*:*:*:*
EPSS
Процентиль: 17%
0.00053
Низкий
5.5 Medium
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-269
Связанные уязвимости
CVSS3: 5.5
debian
больше 5 лет назад
GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2. ...
github
больше 3 лет назад
GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary files because it handles configuration-file errors by printing the configuration file while executing in a setuid root context.
EPSS
Процентиль: 17%
0.00053
Низкий
5.5 Medium
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-269