Описание
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36e7b5d3d or any of the listed versions.
Ссылки
- Mailing ListPatchVendor Advisory
- Mailing ListPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2022-01-03 (исключая)
cpe:2.3:o:google:fuchsia:*:*:*:*:*:*:*:*
EPSS
Процентиль: 3%
0.00016
Низкий
7.5 High
CVSS3
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-732
CWE-732
Связанные уязвимости
CVSS3: 5.5
github
почти 4 года назад
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36e7b5d3d or any of the listed versions.
EPSS
Процентиль: 3%
0.00016
Низкий
7.5 High
CVSS3
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-732
CWE-732