PT-2018-1982 · Astra Linux · Astra Linux
Published
2018-08-23
·
Updated
2018-08-23
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Astra Linux (affected versions not specified)
Description
The issue is related to a buffer overflow error in the file manager of Astra Linux, which can lead to unauthorized access to a locked user session when a specially crafted large string is entered into the password field. Additionally, there are security problems with the sumac utility, resulting in the inability to launch more than one graphical window with a different access level than the current one. Exploitation of this issue can allow a remote attacker to gain unauthorized access to a user's session and cause a denial of service.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux