Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Karel Zak

#17566of 53,638
15.3Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2022-13263
5.5
2022-02-21
Unknown · Util-Linux · CVE-2022-0563
**Name of the Vulnerable Software and Affected Versions** util-linux versions prior to 2.37.4 **Description** A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an `INPUTRC` environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. **Recommendations** For util-linux versions prior to 2.37.4, update to version 2.37.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the `chfn` and `chsh` utilities until a patch is available. Avoid using the `INPUTRC` environment variable in the affected utilities until the issue is resolved.
PT-2017-6832
9.8
2015-09-08
None · Util-Linux · CVE-2015-5224
**Name of the Vulnerable Software and Affected Versions** util-linux (affected versions not specified) **Description** The issue is related to the mkostemp function in login-utils, which can be exploited by remote attackers to cause file name collision and potentially other attacks when used incorrectly. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.