Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

ubuntu логотип

CVE-2023-6917

больше 2 лет назад

A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in privilege levels poses a risk when privileged root processes interact with directories or directory trees owned by unprivileged PCP users. Specifically, this vulnerability may lead to the compromise of PCP user isolation and facilitate local PCP-to-root exploits, particularly through symlink attacks. These vulnerabilities underscore the importance of maintaining robust privilege separation mechanisms within PCP to mitigate the potential for unauthorized privilege escalation.

CVSS3: 6
EPSS: Низкий
redhat логотип

CVE-2023-6917

больше 2 лет назад

A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in privilege levels poses a risk when privileged root processes interact with directories or directory trees owned by unprivileged PCP users. Specifically, this vulnerability may lead to the compromise of PCP user isolation and facilitate local PCP-to-root exploits, particularly through symlink attacks. These vulnerabilities underscore the importance of maintaining robust privilege separation mechanisms within PCP to mitigate the potential for unauthorized privilege escalation.

CVSS3: 6
EPSS: Низкий
nvd логотип

CVE-2023-6917

больше 2 лет назад

A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in privilege levels poses a risk when privileged root processes interact with directories or directory trees owned by unprivileged PCP users. Specifically, this vulnerability may lead to the compromise of PCP user isolation and facilitate local PCP-to-root exploits, particularly through symlink attacks. These vulnerabilities underscore the importance of maintaining robust privilege separation mechanisms within PCP to mitigate the potential for unauthorized privilege escalation.

CVSS3: 6
EPSS: Низкий
debian логотип

CVE-2023-6917

больше 2 лет назад

A vulnerability has been identified in the Performance Co-Pilot (PCP) ...

CVSS3: 6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0801-1

больше 1 года назад

Security update for pcp

EPSS: Низкий
github логотип

GHSA-pgw3-qmf6-36m3

больше 2 лет назад

A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in privilege levels poses a risk when privileged root processes interact with directories or directory trees owned by unprivileged PCP users. Specifically, this vulnerability may lead to the compromise of PCP user isolation and facilitate local PCP-to-root exploits, particularly through symlink attacks. These vulnerabilities underscore the importance of maintaining robust privilege separation mechanisms within PCP to mitigate the potential for unauthorized privilege escalation.

CVSS3: 6
EPSS: Низкий
oracle-oval логотип

ELSA-2024-2213

около 2 лет назад

ELSA-2024-2213: pcp security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2024-06871

больше 2 лет назад

Уязвимость программного обеспечения мониторинга и визуализация производительности Performance Co-Pilot (PCP), связанная с cозданием временного файла с небезопасными разрешениями, позволяющая нарушителю выполнить атаку с использованием символических ссылок и нарушить изоляцию пользователя PCP

CVSS3: 6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3785-1

почти 2 года назад

Security update for pcp

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3976-1

больше 1 года назад

Security update for pcp

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3533-1

почти 2 года назад

Security update for pcp

EPSS: Низкий
redos логотип

ROS-20240904-14

почти 2 года назад

Множественные уязвимости pcp

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-6917

A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in privilege levels poses a risk when privileged root processes interact with directories or directory trees owned by unprivileged PCP users. Specifically, this vulnerability may lead to the compromise of PCP user isolation and facilitate local PCP-to-root exploits, particularly through symlink attacks. These vulnerabilities underscore the importance of maintaining robust privilege separation mechanisms within PCP to mitigate the potential for unauthorized privilege escalation.

CVSS3: 6
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-6917

A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in privilege levels poses a risk when privileged root processes interact with directories or directory trees owned by unprivileged PCP users. Specifically, this vulnerability may lead to the compromise of PCP user isolation and facilitate local PCP-to-root exploits, particularly through symlink attacks. These vulnerabilities underscore the importance of maintaining robust privilege separation mechanisms within PCP to mitigate the potential for unauthorized privilege escalation.

CVSS3: 6
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-6917

A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in privilege levels poses a risk when privileged root processes interact with directories or directory trees owned by unprivileged PCP users. Specifically, this vulnerability may lead to the compromise of PCP user isolation and facilitate local PCP-to-root exploits, particularly through symlink attacks. These vulnerabilities underscore the importance of maintaining robust privilege separation mechanisms within PCP to mitigate the potential for unauthorized privilege escalation.

CVSS3: 6
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-6917

A vulnerability has been identified in the Performance Co-Pilot (PCP) ...

CVSS3: 6
0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2025:0801-1

Security update for pcp

0%
Низкий
больше 1 года назад
github логотип
GHSA-pgw3-qmf6-36m3

A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in privilege levels poses a risk when privileged root processes interact with directories or directory trees owned by unprivileged PCP users. Specifically, this vulnerability may lead to the compromise of PCP user isolation and facilitate local PCP-to-root exploits, particularly through symlink attacks. These vulnerabilities underscore the importance of maintaining robust privilege separation mechanisms within PCP to mitigate the potential for unauthorized privilege escalation.

CVSS3: 6
0%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2024-2213

ELSA-2024-2213: pcp security update (MODERATE)

около 2 лет назад
fstec логотип
BDU:2024-06871

Уязвимость программного обеспечения мониторинга и визуализация производительности Performance Co-Pilot (PCP), связанная с cозданием временного файла с небезопасными разрешениями, позволяющая нарушителю выполнить атаку с использованием символических ссылок и нарушить изоляцию пользователя PCP

CVSS3: 6
0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:3785-1

Security update for pcp

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:3976-1

Security update for pcp

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3533-1

Security update for pcp

почти 2 года назад
redos логотип
ROS-20240904-14

Множественные уязвимости pcp

CVSS3: 9.8
почти 2 года назад

Уязвимостей на страницу