Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

github логотип

GHSA-ppj8-867g-rgjr

около 3 лет назад

A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2023-1386

около 3 лет назад

A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2023-1386

больше 3 лет назад

A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2023-1386

около 3 лет назад

A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.

CVSS3: 3.3
EPSS: Низкий
msrc логотип

CVE-2023-1386

8 месяцев назад

Qemu: 9pfs: suid/sgid bits not dropped on file write

EPSS: Низкий
debian логотип

CVE-2023-1386

около 3 лет назад

A flaw was found in the 9p passthrough filesystem (9pfs) implementatio ...

CVSS3: 3.3
EPSS: Низкий
fstec логотип

BDU:2024-09093

больше 3 лет назад

Уязвимость компонента 9pfs Passthrough Filesystem эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю повысить свои привилегии в системе на хосте

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-ppj8-867g-rgjr

A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.

CVSS3: 3.3
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-1386

A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.

CVSS3: 3.3
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-1386

A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-1386

A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.

CVSS3: 3.3
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-1386

Qemu: 9pfs: suid/sgid bits not dropped on file write

0%
Низкий
8 месяцев назад
debian логотип
CVE-2023-1386

A flaw was found in the 9p passthrough filesystem (9pfs) implementatio ...

CVSS3: 3.3
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2024-09093

Уязвимость компонента 9pfs Passthrough Filesystem эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю повысить свои привилегии в системе на хосте

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу