Описание
"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with privileges, if it's not the case. In the vulnerable version of "loolforkit" this check was wrong, so a normal user could start "loolforkit" and eventually get local root privileges.
Ссылки
- Third Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.2.0 (включая) до 4.2.13 (исключая)Версия от 6.4.0 (включая) до 6.4.3 (исключая)
Одно из
cpe:2.3:a:collaboraoffice:online:*:*:*:*:*:*:*:*
cpe:2.3:a:collaboraoffice:online:*:*:*:*:*:*:*:*
EPSS
Процентиль: 12%
0.0004
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-269
EPSS
Процентиль: 12%
0.0004
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-269