PT-2019-14463 · Slicer69 · Slicer69 Doas

Published

2019-10-18

·

Updated

2024-02-16

·

CVE-2019-15900

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions slicer69 doas versions prior to 6.2
Description An issue was discovered in slicer69 doas where sscanf was used without checking for error cases on platforms without strtonum(3). The uninitialized variable errstr was checked, and in some cases, it returned success even if sscanf failed. This resulted in executing commands as root instead of reporting that the supplied username or group name did not exist.
Recommendations For versions prior to 6.2, update to version 6.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the affected command execution functionality until a patch is available.

Fix

Unchecked Return Value

Incorrect Authorization

Use of Uninitialized Resource

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2019-15900

Affected Products

Slicer69 Doas