Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-1117

Опубликовано: 02 мая 2022
Источник: redhat
CVSS3: 8.4

Описание

A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9fapolicydNot affected
Red Hat Enterprise Linux 8fapolicydFixedRHSA-2022:189810.05.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportfapolicydFixedRHSA-2022:482431.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-552
https://bugzilla.redhat.com/show_bug.cgi?id=2068171fapolicyd: fapolicyd wrongly prepares ld.so path

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
nvd
больше 3 лет назад

A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.

CVSS3: 8.4
msrc
больше 3 лет назад

A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.

rocky
больше 3 лет назад

Moderate: fapolicyd security, bug fix, and enhancement update

CVSS3: 8.4
github
больше 3 лет назад

A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.

oracle-oval
больше 3 лет назад

ELSA-2022-1898: fapolicyd security, bug fix, and enhancement update (MODERATE)

8.4 High

CVSS3