Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-44038

Опубликовано: 19 нояб. 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*
Версия до 1.2.4 (включая)

EPSS

Процентиль: 41%
0.00195
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 4 лет назад

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

CVSS3: 7.3
redhat
около 4 лет назад

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

CVSS3: 7.8
msrc
4 месяца назад

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

CVSS3: 7.8
debian
около 4 лет назад

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod op ...

CVSS3: 7.8
github
около 4 лет назад

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

EPSS

Процентиль: 41%
0.00195
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-59