Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-1326

Опубликовано: 13 апр. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.7

Описание

A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local attacker can escalate privilege. It is extremely unlikely that a system administrator would configure sudo to allow unprivileged users to perform this class of exploit.

РелизСтатусПримечание
bionic

released

2.20.9-0ubuntu7.29
devel

released

2.26.1-0ubuntu2
esm-infra-legacy/trusty

not-affected

esm-infra/bionic

released

2.20.9-0ubuntu7.29
esm-infra/focal

released

2.20.11-0ubuntu27.26
esm-infra/xenial

not-affected

focal

released

2.20.11-0ubuntu27.26
jammy

released

2.20.11-0ubuntu82.4
kinetic

released

2.23.1-0ubuntu3.2
lunar

released

2.26.1-0ubuntu2

Показывать по

EPSS

Процентиль: 88%
0.04087
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
почти 3 года назад

A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local attacker can escalate privilege. It is extremely unlikely that a system administrator would configure sudo to allow unprivileged users to perform this class of exploit.

CVSS3: 7.7
github
почти 3 года назад

A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local attacker can escalate privilege. It is extremely unlikely that a system administrator would configure sudo to allow unprivileged users to perform this class of exploit.

EPSS

Процентиль: 88%
0.04087
Низкий

7.7 High

CVSS3