Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade schroot | Aug 19, 2022 | Aug 19, 2022 |
| Gentoo Linux | — | Upgrade dev-util/schroot. | Oct 31, 2022 | Aug 27, 2022 |
| Ubuntu | — | Upgrade schroot (Ubuntu Pro)Upgrade schroot | Aug 30, 2022 | Aug 27, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub