Логотип exploitDog
bind:CVE-2020-10737
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-10737

Количество 6

Количество 6

ubuntu логотип

CVE-2020-10737

больше 5 лет назад

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2020-10737

почти 6 лет назад

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2020-10737

больше 5 лет назад

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2020-10737

больше 5 лет назад

A race condition was found in the mkhomedir tool shipped with the oddj ...

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-m6xw-hhwx-7qjc

больше 3 лет назад

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
EPSS: Низкий
oracle-oval логотип

ELSA-2020-4687

около 5 лет назад

ELSA-2020-4687: oddjob security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-10737

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-10737

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-10737

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-10737

A race condition was found in the mkhomedir tool shipped with the oddj ...

CVSS3: 6.3
0%
Низкий
больше 5 лет назад
github логотип
GHSA-m6xw-hhwx-7qjc

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2020-4687

ELSA-2020-4687: oddjob security, bug fix, and enhancement update (MODERATE)

около 5 лет назад

Уязвимостей на страницу