PT-2021-23286 · Seatd · Seatd

Simon Ser

·

Published

2021-09-17

·

Updated

2022-07-12

·

CVE-2021-41387

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions seatd versions 0.6.x before 0.6.2 seatd version 0.6.0 through 0.6.1
Description The issue allows privilege escalation because it uses execlp and may be installed setuid root.
Recommendations For seatd versions 0.6.x before 0.6.2, update to version 0.6.2 or later to resolve the issue. For seatd version 0.6.0 through 0.6.1, update to version 0.6.2 or later to resolve the issue.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41387

Affected Products

Seatd