PT-2023-27371 · Gnu+2 · Gnu Inetutils+2

Jeffrey

·

Published

2023-08-13

·

Updated

2025-09-28

·

CVE-2023-40303

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU inetutils versions prior to 2.5
Description The issue allows privilege escalation due to unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
Recommendations For GNU inetutils versions prior to 2.5, update to version 2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the set*id() family functions in the affected services until a patch is available.

Exploit

Fix

Unchecked Return Value

Weakness Enumeration

Related Identifiers

CVE-2023-40303
DLA-3611-1
USN-6304-1
USN-7781-1

Affected Products

Gnu Inetutils
Linuxmint
Ubuntu