Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-40303
HistoryAug 14, 2023 - 12:00 a.m.

CVE-2023-40303

2023-08-1400:00:00
ubuntu.com
ubuntu.com
30
cve-2023-40303
privilege escalation
unchecked return values
set*id functions
ftpd
rcp
rlogin
rsh
rshd
uucpd
setuid system call
unix

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

GNU inetutils before 2.5 may allow privilege escalation because of
unchecked return values of set*id() family functions in ftpd, rcp, rlogin,
rsh, rshd, and uucpd. This is, for example, relevant if the setuid system
call fails when a process is trying to drop privileges before letting an
ordinary user control the activities of the process.

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%