Описание
monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows local users to gain privileges via a Trojan horse library in the current working directory.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.17.1.0 (исключая)
cpe:2.3:a:getmonero:monero:*:*:*:*:*:*:*:*
EPSS
Процентиль: 16%
0.0005
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-427
Связанные уязвимости
CVSS3: 7.8
github
больше 3 лет назад
monero-wallet-gui in Monero GUI 0.17.0.1 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows local users to gain privileges via a Trojan horse library in the current working directory.
EPSS
Процентиль: 16%
0.0005
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-427