Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-29799
HistoryApr 27, 2022 - 12:00 a.m.

CVE-2022-29799

2022-04-2700:00:00
ubuntu.com
ubuntu.com
23
vulnerability
networkd-dispatcher
unsanitized functions
directory traversal

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

25.9%

A vulnerability was found in networkd-dispatcher. This flaw exists because
no functions are sanitized by the OperationalState or the
AdministrativeState of networkd-dispatcher. This attack leads to a
directory traversal to escape from the “/etc/networkd-dispatcher” base
directory.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchnetworkd-dispatcher< 1.7-0ubuntu3.5UNKNOWN
ubuntu20.04noarchnetworkd-dispatcher< 2.1-2~ubuntu20.04.3UNKNOWN
ubuntu21.10noarchnetworkd-dispatcher< 2.1-2ubuntu0.21.10.2UNKNOWN
ubuntu22.04noarchnetworkd-dispatcher< 2.1-2ubuntu0.22.04.2UNKNOWN

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

25.9%