Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-29906

Опубликовано: 29 апр. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.6

Описание

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the tty configuration directive that can bypass /bin/login, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.

РелизСтатусПримечание
devel

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

needs-triage

noble

needs-triage

oracular

ignored

end of life, was needs-triage
plucky

ignored

end of life, was needs-triage
questing

needs-triage

Показывать по

EPSS

Процентиль: 5%
0.00021
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
nvd
9 месяцев назад

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.

CVSS3: 8.6
debian
9 месяцев назад

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 ...

CVSS3: 8.6
fstec
11 месяцев назад

Уязвимость компонента getty системы инициализации finit, позволяющая нарушителю получить несанкционированный доступ к системе

EPSS

Процентиль: 5%
0.00021
Низкий

8.6 High

CVSS3