PT-2019-19974 · Gns3 · Gns3 Server+1
Publicado
2019-05-31
·
Atualizado
2021-07-21
·
CVE-2020-14976
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GNS3 ubridge versions 0.9.18 and earlier
GNS3 server versions prior to 2.1.17
Description
The issue allows a local attacker to read arbitrary files because it handles configuration-file errors by printing the configuration file while executing in a setuid root context.
Recommendations
For GNS3 ubridge versions 0.9.18 and earlier, update to a version later than 0.9.18 to resolve the issue.
For GNS3 server versions prior to 2.1.17, update to version 2.1.17 or later to resolve the issue.
Exploit
Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gns3 Server
Gns3 Ubridge