Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-6964

Опубликовано: 28 мар. 2017
Источник: ubuntu
Приоритет: medium
CVSS2: 7.2
CVSS3: 7.8

Описание

dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) setuid or (2) setgid function, which might cause dmcrypt-get-device to execute code, which was intended to run as an unprivileged user, as root. This affects eject through 2.1.5+deb1+cvs20081104-13.1 on Debian, eject before 2.1.5+deb1+cvs20081104-13.1ubuntu0.16.10.1 on Ubuntu 16.10, eject before 2.1.5+deb1+cvs20081104-13.1ubuntu0.16.04.1 on Ubuntu 16.04 LTS, eject before 2.1.5+deb1+cvs20081104-13.1ubuntu0.14.04.1 on Ubuntu 14.04 LTS, and eject before 2.1.5+deb1+cvs20081104-9ubuntu0.1 on Ubuntu 12.04 LTS.

РелизСтатусПримечание
devel

released

2.1.5+deb1+cvs20081104-13.2
esm-infra-legacy/trusty

released

2.1.5+deb1+cvs20081104-13.1ubuntu0.14.04.1
esm-infra/xenial

released

2.1.5+deb1+cvs20081104-13.1ubuntu0.16.04.1
precise

released

2.1.5+deb1+cvs20081104-9ubuntu0.1
precise/esm

not-affected

2.1.5+deb1+cvs20081104-9ubuntu0.1
trusty

released

2.1.5+deb1+cvs20081104-13.1ubuntu0.14.04.1
trusty/esm

released

2.1.5+deb1+cvs20081104-13.1ubuntu0.14.04.1
upstream

needed

vivid/stable-phone-overlay

ignored

end of life
vivid/ubuntu-core

DNE

Показывать по

7.2 High

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
почти 9 лет назад

dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) setuid or (2) setgid function, which might cause dmcrypt-get-device to execute code, which was intended to run as an unprivileged user, as root. This affects eject through 2.1.5+deb1+cvs20081104-13.1 on Debian, eject before 2.1.5+deb1+cvs20081104-13.1ubuntu0.16.10.1 on Ubuntu 16.10, eject before 2.1.5+deb1+cvs20081104-13.1ubuntu0.16.04.1 on Ubuntu 16.04 LTS, eject before 2.1.5+deb1+cvs20081104-13.1ubuntu0.14.04.1 on Ubuntu 14.04 LTS, and eject before 2.1.5+deb1+cvs20081104-9ubuntu0.1 on Ubuntu 12.04 LTS.

CVSS3: 7.8
debian
почти 9 лет назад

dmcrypt-get-device, as shipped in the eject package of Debian and Ubun ...

CVSS3: 7.8
github
больше 3 лет назад

dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) setuid or (2) setgid function, which might cause dmcrypt-get-device to execute code, which was intended to run as an unprivileged user, as root. This affects eject through 2.1.5+deb1+cvs20081104-13.1 on Debian, eject before 2.1.5+deb1+cvs20081104-13.1ubuntu0.16.10.1 on Ubuntu 16.10, eject before 2.1.5+deb1+cvs20081104-13.1ubuntu0.16.04.1 on Ubuntu 16.04 LTS, eject before 2.1.5+deb1+cvs20081104-13.1ubuntu0.14.04.1 on Ubuntu 14.04 LTS, and eject before 2.1.5+deb1+cvs20081104-9ubuntu0.1 on Ubuntu 12.04 LTS.

fstec
почти 9 лет назад

Уязвимость операционных систем Ubuntu и Debian GNU/Linux, позволяющая нарушителю повысить свои привилегии

7.2 High

CVSS2

7.8 High

CVSS3