Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-5369

Опубликовано: 04 окт. 2023
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Before correction, the copy_file_range system call checked only for the CAP_READ and CAP_WRITE capabilities on the input and output file descriptors, respectively. Using an offset is logically equivalent to seeking, and the system call must additionally require the CAP_SEEK capability.

This incorrect privilege check enabled sandboxed processes with only read or write but no seek capability on a file descriptor to read data from or write data to an arbitrary location within the file corresponding to that file descriptor.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:freebsd:freebsd:13.2:-:*:*:*:*:*:*

EPSS

Процентиль: 23%
0.00078
Низкий

7.1 High

CVSS3

Дефекты

CWE-273
CWE-273

Связанные уязвимости

CVSS3: 7.1
github
больше 2 лет назад

Before correction, the copy_file_range system call checked only for the CAP_READ and CAP_WRITE capabilities on the input and output file descriptors, respectively. Using an offset is logically equivalent to seeking, and the system call must additionally require the CAP_SEEK capability. This incorrect privilege check enabled sandboxed processes with only read or write but no seek capability on a file descriptor to read data from or write data to an arbitrary location within the file corresponding to that file descriptor.

EPSS

Процентиль: 23%
0.00078
Низкий

7.1 High

CVSS3

Дефекты

CWE-273
CWE-273