PT-2022-2378 · Unknown+3 · Networkd-Dispatcher+3

Published

2022-04-26

·

Updated

2022-09-23

·

CVE-2022-29799

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions networkd-dispatcher (affected versions not specified)
Description A flaw exists in networkd-dispatcher due to the lack of sanitization of functions by the OperationalState or the AdministrativeState, leading to a directory traversal attack. This attack can allow an attacker to escape from the "/etc/networkd-dispatcher" base directory, potentially resulting in privilege escalation or arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2022-02730
CVE-2022-29799
USN-5395-1
USN-5395-2

Affected Products

Debian
Linuxmint
Ubuntu
Networkd-Dispatcher