Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-21583

Опубликовано: 22 авг. 2023
Источник: redhat
CVSS3: 6.4

Описание

An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.

A vulnerability was found in hwclock in util-linux, which allowed non-root users to access the hardware clock. This flaw allows an attacker to execute arbitrary code via the path parameter when setting the date.

Отчет

This presents an issue only in scenarios where the administrator has configured hwclock to be setuid root. However, it's important to note that this is a non-default and unlikely configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7util-linuxOut of support scope
Red Hat Enterprise Linux 8util-linuxNot affected
Red Hat Enterprise Linux 9util-linuxNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2238716util-linux: arbitrary commands execution via the path parameter

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
больше 2 лет назад

An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.

CVSS3: 6.7
nvd
больше 2 лет назад

An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.

CVSS3: 6.7
debian
больше 2 лет назад

An issue was discovered in hwclock.13-v2.27 allows attackers to gain e ...

CVSS3: 6.7
github
больше 2 лет назад

An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.

6.4 Medium

CVSS3