GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade inetutils | Oct 10, 2023 | Aug 14, 2023 |
| Ubuntu | — | Upgrade inetutils-tools (Ubuntu Pro)Upgrade inetutils-ping (Ubuntu Pro)Upgrade inetutils-ftp (Ubuntu Pro)Upgrade inetutils-telnet (Ubuntu Pro)Upgrade inetutils-toolsUpgrade inetutils-syslogd (Ubuntu Pro)Upgrade inetutils-talk (Ubuntu Pro)Upgrade inetutils-ftpd (Ubuntu Pro)Upgrade inetutils-inetd (Ubuntu Pro)Upgrade inetutils-traceroute (Ubuntu Pro)Upgrade inetutils-telnetd | Aug 23, 2023 | Aug 14, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub