GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
References
Configurations
History
02 Jan 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
Summary | GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process. |
31 Dec 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
08 Oct 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 Aug 2023, 14:24
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-252 | |
CPE | cpe:2.3:a:gnu:inetutils:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
First Time |
Gnu inetutils
Gnu |
|
References | (MISC) https://lists.gnu.org/archive/html/bug-inetutils/2023-07/msg00000.html - Exploit, Mailing List, Patch, Vendor Advisory | |
References | (MISC) https://ftp.gnu.org/gnu/inetutils/ - Product | |
References | (MISC) https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=e4e65c03f4c11292a3e40ef72ca3f194c8bffdd6 - Patch |
14 Aug 2023, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-14 05:15
Updated : 2024-02-28 20:33
NVD link : CVE-2023-40303
Mitre link : CVE-2023-40303
CVE.ORG link : CVE-2023-40303
JSON object : View
Products Affected
gnu
- inetutils
CWE
CWE-252
Unchecked Return Value