PT-2023-17049 · Sccache+2 · Sccache+2
Paolo Tranquilli
+1
·
Published
2023-05-30
·
Updated
2025-10-15
·
CVE-2023-1521
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
sccache versions prior to 0.4.0
Description
The sccache client can execute arbitrary code with the privileges of a local sccache server by preloading the code in a shared library passed to
LD PRELOAD. If the server is run as root, which is the default when installing the snap package, this means a user running the sccache client can get root privileges.Recommendations
Upgrade to version 0.4.0
As a temporary workaround, do not run the sccache server as root.
Exploit
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Suse
Sccache