Логотип exploitDog
bind:"GHSA-m46g-8pc6-m8q7" OR bind:"CVE-2022-3787"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-m46g-8pc6-m8q7" OR bind:"CVE-2022-3787"

Количество 7

Количество 7

github логотип

GHSA-m46g-8pc6-m8q7

больше 2 лет назад

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-3787

почти 3 года назад

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2022-3787

больше 2 лет назад

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.

CVSS3: 7.8
EPSS: Низкий
rocky логотип

RLSA-2022:8453

больше 2 лет назад

Important: device-mapper-multipath security update

EPSS: Низкий
rocky логотип

RLSA-2022:7928

больше 2 лет назад

Important: device-mapper-multipath security update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8453

больше 2 лет назад

ELSA-2022-8453: device-mapper-multipath security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7928

больше 2 лет назад

ELSA-2022-7928: device-mapper-multipath security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m46g-8pc6-m8q7

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-3787

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.

CVSS3: 8.4
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-3787

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2022:8453

Important: device-mapper-multipath security update

0%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2022:7928

Important: device-mapper-multipath security update

0%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2022-8453

ELSA-2022-8453: device-mapper-multipath security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2022-7928

ELSA-2022-7928: device-mapper-multipath security update (IMPORTANT)

больше 2 лет назад

Уязвимостей на страницу