Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31256

Опубликовано: 26 окт. 2022
Источник: nvd
CVSS3: 7.7
CVSS3: 7.8
EPSS Низкий

Описание

A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:opensuse:factory:*:*:*:*:*:*:*:*
Версия до 8.17.1-1.1 (исключая)

EPSS

Процентиль: 33%
0.00128
Низкий

7.7 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.7
debian
больше 3 лет назад

A Improper Link Resolution Before File Access ('Link Following') vulne ...

suse-cvrf
около 3 лет назад

Security update for sendmail

suse-cvrf
около 3 лет назад

Security update for sendmail

CVSS3: 7.8
github
больше 3 лет назад

A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.

EPSS

Процентиль: 33%
0.00128
Низкий

7.7 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-59