[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2022-1901 --- util-linux

ID: oval:org.secpod.oval:def:1701070Date: (C)2022-12-08   (M)2024-01-08
Class: PATCHFamily: unix




A flaw was found in the Linux kernel's util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an 'INPUTRC' environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation

Platform:
Amazon Linux 2
Product:
util-linux
libfdisk
libsmartcols
libmount
libblkid
libuuid
uuidd
python-libmount
Reference:
ALAS2-2022-1901
CVE-2022-0563
CVE    1
CVE-2022-0563
CPE    3
cpe:/a:linux:util-linux
cpe:/o:amazon:linux:2
cpe:/a:uuidd:uuidd

© SecPod Technologies