Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

github логотип

GHSA-cq92-4vj3-mcq8

больше 1 года назад

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2025-1390

больше 1 года назад

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2025-1390

больше 1 года назад

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2025-1390

больше 1 года назад

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2025-1390

больше 1 года назад

pam_cap: Fix potential configuration parsing error

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2025-1390

больше 1 года назад

The PAM module pam_cap.so of libcap configuration supports group names ...

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2025-02012

больше 1 года назад

Уязвимость PAM-модуля pam_cap.so библиотеки libcap, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-cq92-4vj3-mcq8

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-1390

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2025-1390

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-1390

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-1390

pam_cap: Fix potential configuration parsing error

CVSS3: 6.1
0%
Низкий
больше 1 года назад
debian логотип
CVE-2025-1390

The PAM module pam_cap.so of libcap configuration supports group names ...

CVSS3: 6.1
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-02012

Уязвимость PAM-модуля pam_cap.so библиотеки libcap, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу