PT-2022-2284 · Swhkd · Swhkd

Mgerstner

·

Published

2022-03-29

·

Updated

2022-10-27

·

CVE-2022-27816

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions SWHKD version 1.1.5
Description The issue is related to the unsafe use of the /tmp/swhks.pid pathname, which can lead to data loss or a denial of service. An attacker could exploit this to impact data integrity or cause a service disruption. The vulnerability is associated with the possibility of saving the process ID to the /tmp/swhks.pid file and inserting the ID of an existing process.
Recommendations For SWHKD version 1.1.5, consider updating to a version where the issue is fixed, as a patch is available on the 1.1.0 branch of the repository. As a temporary workaround, consider restricting access to the /tmp/swhks.pid file to minimize the risk of exploitation.

Exploit

Fix

Link Following

Weakness Enumeration

Related Identifiers

BDU:2022-02459
CVE-2022-27816
GHSA-8M49-2XJ8-67V9

Affected Products

Swhkd