Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-0563

Опубликовано: 21 фев. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 1.9
CVSS3: 5.5

Описание

A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.

РелизСтатусПримечание
bionic

not-affected

code not compiled
devel

not-affected

code not compiled
esm-infra-legacy/trusty

not-affected

code not compiled
esm-infra/bionic

not-affected

code not compiled
esm-infra/focal

not-affected

code not compiled
esm-infra/xenial

not-affected

code not compiled
focal

not-affected

code not compiled
impish

not-affected

code not compiled
trusty

ignored

end of standard support
trusty/esm

not-affected

code not compiled

Показывать по

EPSS

Процентиль: 4%
0.0002
Низкий

1.9 Low

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
почти 4 года назад

A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.

CVSS3: 5.5
nvd
почти 4 года назад

A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.

CVSS3: 5.5
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 5.5
debian
почти 4 года назад

A flaw was found in the util-linux chfn and chsh utilities when compil ...

CVSS3: 5.5
github
почти 4 года назад

A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.

EPSS

Процентиль: 4%
0.0002
Низкий

1.9 Low

CVSS2

5.5 Medium

CVSS3