Логотип exploitDog
bind:"GHSA-w2gm-3gx9-m2p2" OR bind:"CVE-2022-3560"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-w2gm-3gx9-m2p2" OR bind:"CVE-2022-3560"

Количество 15

Количество 15

github логотип

GHSA-w2gm-3gx9-m2p2

почти 3 года назад

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2022-3560

почти 3 года назад

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-3560

почти 3 года назад

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2022-3560

почти 3 года назад

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2022-3560

2 месяца назад

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2022-3560

почти 3 года назад

A flaw was found in pesign. The pesign package provides a systemd serv ...

CVSS3: 5.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0484-1

почти 3 года назад

Security update for pesign

EPSS: Низкий
rocky логотип

RLSA-2023:1572

больше 2 лет назад

Important: pesign security update

EPSS: Низкий
rocky логотип

RLSA-2023:1067

больше 2 лет назад

Important: pesign security update

EPSS: Низкий
oracle-oval логотип

ELSA-2023-1572

больше 2 лет назад

ELSA-2023-1572: pesign security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-1093

больше 2 лет назад

ELSA-2023-1093: pesign security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-1067

больше 2 лет назад

ELSA-2023-1067: pesign security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2023-00640

почти 3 года назад

Уязвимость демона pesign подсистемы инициализации и управления службами systemd, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20240426-03

больше 1 года назад

Уязвимость efivar

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20240426-01

больше 1 года назад

Уязвимость pesign

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-w2gm-3gx9-m2p2

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-3560

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-3560

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-3560

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
msrc логотип
CVE-2022-3560

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.

CVSS3: 5.5
0%
Низкий
2 месяца назад
debian логотип
CVE-2022-3560

A flaw was found in pesign. The pesign package provides a systemd serv ...

CVSS3: 5.5
0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:0484-1

Security update for pesign

0%
Низкий
почти 3 года назад
rocky логотип
RLSA-2023:1572

Important: pesign security update

0%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2023:1067

Important: pesign security update

0%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2023-1572

ELSA-2023-1572: pesign security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2023-1093

ELSA-2023-1093: pesign security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2023-1067

ELSA-2023-1067: pesign security update (IMPORTANT)

больше 2 лет назад
fstec логотип
BDU:2023-00640

Уязвимость демона pesign подсистемы инициализации и управления службами systemd, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.8
0%
Низкий
почти 3 года назад
redos логотип
ROS-20240426-03

Уязвимость efivar

CVSS3: 7.8
0%
Низкий
больше 1 года назад
redos логотип
ROS-20240426-01

Уязвимость pesign

CVSS3: 7.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу