Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10151

Опубликовано: 03 мая 2016
Источник: redhat
CVSS3: 7
CVSS2: 3.7
EPSS Низкий

Описание

The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID with UID to determine whether to use configurations from environment variables, which allows local users to gain privileges via the (1) HESIOD_CONFIG or (2) HES_DOMAIN environment variable and leveraging certain SUID/SGUID binary.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5hesiodWill not fix
Red Hat Enterprise Linux 6hesiodWill not fix
Red Hat Enterprise Linux 7hesiodWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-547
https://bugzilla.redhat.com/show_bug.cgi?id=1332508hesiod: Weak SUID check allowing privilege elevation

EPSS

Процентиль: 31%
0.00116
Низкий

7 High

CVSS3

3.7 Low

CVSS2

Связанные уязвимости

CVSS3: 7
ubuntu
почти 9 лет назад

The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID with UID to determine whether to use configurations from environment variables, which allows local users to gain privileges via the (1) HESIOD_CONFIG or (2) HES_DOMAIN environment variable and leveraging certain SUID/SGUID binary.

CVSS3: 7
nvd
почти 9 лет назад

The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID with UID to determine whether to use configurations from environment variables, which allows local users to gain privileges via the (1) HESIOD_CONFIG or (2) HES_DOMAIN environment variable and leveraging certain SUID/SGUID binary.

CVSS3: 7
debian
почти 9 лет назад

The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID ...

CVSS3: 7
github
больше 3 лет назад

The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID with UID to determine whether to use configurations from environment variables, which allows local users to gain privileges via the (1) HESIOD_CONFIG or (2) HES_DOMAIN environment variable and leveraging certain SUID/SGUID binary.

EPSS

Процентиль: 31%
0.00116
Низкий

7 High

CVSS3

3.7 Low

CVSS2