Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

fstec логотип

BDU:2026-06434

больше 6 лет назад

Уязвимость компонента /etc/skel демона для выполнения задач по запросу других приложений Oddjob, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2020-10737

около 6 лет назад

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2020-10737

больше 6 лет назад

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2020-10737

около 6 лет назад

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2020-10737

около 6 лет назад

A race condition was found in the mkhomedir tool shipped with the oddj ...

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-m6xw-hhwx-7qjc

около 4 лет назад

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
EPSS: Низкий
oracle-oval логотип

ELSA-2020-4687

больше 5 лет назад

ELSA-2020-4687: oddjob security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-06434

Уязвимость компонента /etc/skel демона для выполнения задач по запросу других приложений Oddjob, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.3
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2020-10737

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
0%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-10737

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-10737

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
0%
Низкий
около 6 лет назад
debian логотип
CVE-2020-10737

A race condition was found in the mkhomedir tool shipped with the oddj ...

CVSS3: 6.3
0%
Низкий
около 6 лет назад
github логотип
GHSA-m6xw-hhwx-7qjc

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
0%
Низкий
около 4 лет назад
oracle-oval логотип
ELSA-2020-4687

ELSA-2020-4687: oddjob security, bug fix, and enhancement update (MODERATE)

больше 5 лет назад

Уязвимостей на страницу