Show plain JSON{"id": "CVE-2017-16638", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 10.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C", "authentication": "NONE", "integrityImpact": "COMPLETE", "accessComplexity": "LOW", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2017-11-06T23:29:00.297", "references": [{"url": "https://bugs.gentoo.org/603382", "tags": ["Issue Tracking", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://security.gentoo.org/glsa/201711-11", "tags": ["Issue Tracking", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://bugs.gentoo.org/603382", "tags": ["Issue Tracking", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://security.gentoo.org/glsa/201711-11", "tags": ["Issue Tracking", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-732"}]}], "descriptions": [{"lang": "en", "value": "The Gentoo net-misc/vde package before version 2.3.2-r4 may allow members of the \"qemu\" group to gain root privileges by creating a hard link in a directory on which \"chown\" is called recursively by the OpenRC service script."}, {"lang": "es", "value": "El paquete de Gentoo net-misc/vde en versiones anteriores a la 2.3.2-r4 podr\u00eda permitir que miembros del grupo \"qemu\" obtengan privilegios root mediante la creaci\u00f3n de un v\u00ednculo f\u00edsico en un directorio en el que \"chown\" es llamado recursivamente por el script de servicio OpenRC."}], "lastModified": "2024-11-21T03:16:44.053", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:vde_project:vde:*:r4:*:*:*:gentoo:*:*", "vulnerable": true, "matchCriteriaId": "8109690A-D695-4D1C-8C7A-CBD004CA9888", "versionEndExcluding": "2.3.2"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}