Lucene search

K
cvelistSuseCVELIST:CVE-2022-31256
HistoryOct 26, 2022 - 12:00 a.m.

CVE-2022-31256 sendmail: mail to root privilege escalation via sm-client.pre script

2022-10-2600:00:00
CWE-59
suse
www.cve.org
1
cve-2022-31256
sendmail
privilege escalation
opensuse factory
vulnerability
suse

7.7 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

0.0004 Low

EPSS

Percentile

5.1%

A Improper Link Resolution Before File Access (‘Link Following’) vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.

CNA Affected

[
  {
    "vendor": "SUSE",
    "product": "openSUSE Factory",
    "versions": [
      {
        "version": "sendmail",
        "status": "affected",
        "lessThan": "8.17.1-1.1",
        "versionType": "custom"
      }
    ]
  }
]

7.7 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

0.0004 Low

EPSS

Percentile

5.1%

Related for CVELIST:CVE-2022-31256