Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-49298

Опубликовано: 24 нояб. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always security related, but can be security related in realistic situations. A possible example is cp, from a recent GNU Core Utilities (coreutils) version, when attempting to preserve a rule set for denying unauthorized access. (One might use cp when configuring access control, such as with the /etc/hosts.deny file specified in the IBM Support reference.) NOTE: this issue occurs less often in version 2.2.1, and in versions before 2.1.4, because of the default configuration in those versions.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

released

2.2.2-0ubuntu2
esm-apps/xenial

needed

esm-infra/bionic

needed

esm-infra/focal

not-affected

0.8.3-1ubuntu12.17
esm-infra/xenial

needed

focal

released

0.8.3-1ubuntu12.17
jammy

released

2.1.5-1ubuntu6~22.04.4
lunar

ignored

end of life, was needed
mantic

released

2.2.0-0ubuntu1~23.10.3

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always security related, but can be security related in realistic situations. A possible example is cp, from a recent GNU Core Utilities (coreutils) version, when attempting to preserve a rule set for denying unauthorized access. (One might use cp when configuring access control, such as with the /etc/hosts.deny file specified in the IBM Support reference.) NOTE: this issue occurs less often in version 2.2.1, and in versions before 2.1.4, because of the default configuration in those versions.

CVSS3: 7.5
debian
больше 1 года назад

OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios i ...

CVSS3: 7.5
redos
9 месяцев назад

Уязвимость zfs

CVSS3: 7.5
github
больше 1 года назад

OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always security related, but can be security related in realistic situations. A possible example is cp, from a recent GNU Core Utilities (coreutils) version, when attempting to preserve a rule set for denying unauthorized access. (One might use cp when configuring access control, such as with the /etc/hosts.deny file specified in the IBM Support reference.) NOTE: this issue occurs less often in version 2.2.1, and in versions before 2.1.4, because of the default configuration in those versions.

7.5 High

CVSS3