Lucene search

K
osvGoogleOSV:CVE-2023-40303
HistoryAug 14, 2023 - 5:15 a.m.

CVE-2023-40303

2023-08-1405:15:00
Google
osv.dev
11
gnu inetutils
privilege escalation
unchecked return values

7.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

GNU inetutils through 2.4 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.

7.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%