PT-2022-2378 · Unknown+3 · Networkd-Dispatcher+3
Published
2022-04-26
·
Updated
2022-09-23
·
CVE-2022-29799
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
networkd-dispatcher (affected versions not specified)
Description
A flaw exists in networkd-dispatcher due to the lack of sanitization of functions by the OperationalState or the AdministrativeState, leading to a directory traversal attack. This attack can allow an attacker to escape from the "/etc/networkd-dispatcher" base directory, potentially resulting in privilege escalation or arbitrary code execution.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Ubuntu
Networkd-Dispatcher