Логотип exploitDog
bind:"GHSA-qv29-rjwj-jjrm" OR bind:"CVE-2022-47952"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-qv29-rjwj-jjrm" OR bind:"CVE-2022-47952"

Количество 7

Количество 7

github логотип

GHSA-qv29-rjwj-jjrm

почти 3 года назад

lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that "we will report back to the user that the open() failed but the user has no way of knowing why it failed"; however, in many realistic cases, there are no plausible reasons for failing except that the file does not exist.

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2022-47952

почти 3 года назад

lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that "we will report back to the user that the open() failed but the user has no way of knowing why it failed"; however, in many realistic cases, there are no plausible reasons for failing except that the file does not exist.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2022-47952

почти 3 года назад

lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that "we will report back to the user that the open() failed but the user has no way of knowing why it failed"; however, in many realistic cases, there are no plausible reasons for failing except that the file does not exist.

CVSS3: 3.3
EPSS: Низкий
debian логотип

CVE-2022-47952

почти 3 года назад

lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may al ...

CVSS3: 3.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2024:0342-1

около 1 года назад

Security update for lxc

EPSS: Низкий
redos логотип

ROS-20240625-02

больше 1 года назад

Уязвимость lxc

CVSS3: 3.3
EPSS: Низкий
fstec логотип

BDU:2024-04921

почти 3 года назад

Уязвимость компонента lxc-user-nic системы виртуализации LXC, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-qv29-rjwj-jjrm

lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that "we will report back to the user that the open() failed but the user has no way of knowing why it failed"; however, in many realistic cases, there are no plausible reasons for failing except that the file does not exist.

CVSS3: 3.3
2%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-47952

lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that "we will report back to the user that the open() failed but the user has no way of knowing why it failed"; however, in many realistic cases, there are no plausible reasons for failing except that the file does not exist.

CVSS3: 3.3
2%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-47952

lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that "we will report back to the user that the open() failed but the user has no way of knowing why it failed"; however, in many realistic cases, there are no plausible reasons for failing except that the file does not exist.

CVSS3: 3.3
2%
Низкий
почти 3 года назад
debian логотип
CVE-2022-47952

lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may al ...

CVSS3: 3.3
2%
Низкий
почти 3 года назад
suse-cvrf логотип
openSUSE-SU-2024:0342-1

Security update for lxc

2%
Низкий
около 1 года назад
redos логотип
ROS-20240625-02

Уязвимость lxc

CVSS3: 3.3
2%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-04921

Уязвимость компонента lxc-user-nic системы виртуализации LXC, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.3
2%
Низкий
почти 3 года назад

Уязвимостей на страницу