uptimed before 0.4.6-r1 on Gentoo allows local users (with access to the uptimed user account) to gain root privileges by creating a hard link within the /var/spool/uptimed directory, because there is an unsafe chown -R call.
References
Link | Resource |
---|---|
https://bugs.gentoo.org/630810 | Exploit Patch Third Party Advisory |
Configurations
Information
Published : 2023-01-26 13:15
Updated : 2023-02-03 11:49
NVD link : CVE-2020-36657
Mitre link : CVE-2020-36657
JSON object : View
CWE
Products Affected
uptimed_project
- uptimed