PT-2019-19974 · Gns3 · Gns3 Server+1
Published
2019-05-31
·
Updated
2021-07-21
·
CVE-2020-14976
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GNS3 ubridge versions 0.9.18 and earlier
GNS3 server versions prior to 2.1.17
Description
The issue allows a local attacker to read arbitrary files because it handles configuration-file errors by printing the configuration file while executing in a setuid root context.
Recommendations
For GNS3 ubridge versions 0.9.18 and earlier, update to a version later than 0.9.18 to resolve the issue.
For GNS3 server versions prior to 2.1.17, update to version 2.1.17 or later to resolve the issue.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gns3 Server
Gns3 Ubridge