Логотип exploitDog
bind:"BDU:2025-02012" OR bind:"CVE-2025-1390"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-02012" OR bind:"CVE-2025-1390"

Количество 7

Количество 7

fstec логотип

BDU:2025-02012

12 месяцев назад

Уязвимость PAM-модуля pam_cap.so библиотеки libcap, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2025-1390

12 месяцев назад

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2025-1390

12 месяцев назад

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2025-1390

12 месяцев назад

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2025-1390

12 месяцев назад

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2025-1390

12 месяцев назад

The PAM module pam_cap.so of libcap configuration supports group names ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-cq92-4vj3-mcq8

12 месяцев назад

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-02012

Уязвимость PAM-модуля pam_cap.so библиотеки libcap, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.1
0%
Низкий
12 месяцев назад
ubuntu логотип
CVE-2025-1390

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
0%
Низкий
12 месяцев назад
redhat логотип
CVE-2025-1390

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
0%
Низкий
12 месяцев назад
nvd логотип
CVE-2025-1390

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
0%
Низкий
12 месяцев назад
msrc логотип
CVSS3: 6.1
0%
Низкий
12 месяцев назад
debian логотип
CVE-2025-1390

The PAM module pam_cap.so of libcap configuration supports group names ...

CVSS3: 6.1
0%
Низкий
12 месяцев назад
github логотип
GHSA-cq92-4vj3-mcq8

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
0%
Низкий
12 месяцев назад

Уязвимостей на страницу