PT-2023-27371 · Gnu+2 · Gnu Inetutils+2

Jeffrey

·

Publicado

2023-08-13

·

Atualizado

2025-09-28

·

CVE-2023-40303

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU inetutils versions prior to 2.5
Description The issue allows privilege escalation due to unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
Recommendations For GNU inetutils versions prior to 2.5, update to version 2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the set*id() family functions in the affected services until a patch is available.

Exploit

Correção

Unchecked Return Value

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-40303
DLA-3611-1
USN-6304-1
USN-7781-1

Produtos afetados

Gnu Inetutils
Linuxmint
Ubuntu