A Improper Privilege Management vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local users to gain the privileges of the tty and dialout groups and access and manipulate any running cscreen seesion. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.
                
            References
                    | Link | Resource | 
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1196451 | Exploit Issue Tracking Vendor Advisory | 
| https://bugzilla.suse.com/show_bug.cgi?id=1196451 | Exploit Issue Tracking Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    21 Nov 2024, 06:45
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://bugzilla.suse.com/show_bug.cgi?id=1196451 - Exploit, Issue Tracking, Vendor Advisory | 
14 Apr 2023, 18:48
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-732 | |
| CVSS | v2 : v3 : | v2 : 4.6 v3 : 5.3 | 
22 Mar 2022, 16:08
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:opensuse:cscreen:*:*:*:*:*:*:*:* cpe:2.3:a:opensuse:factory:-:*:*:*:*:*:*:* | |
| CVSS | v2 : v3 : | v2 : 4.6 v3 : 7.8 | 
| References | (CONFIRM) https://bugzilla.suse.com/show_bug.cgi?id=1196451 - Exploit, Issue Tracking, Vendor Advisory | 
16 Mar 2022, 11:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2022-03-16 10:15
Updated : 2024-11-21 06:45
NVD link : CVE-2022-21946
Mitre link : CVE-2022-21946
CVE.ORG link : CVE-2022-21946
JSON object : View
Products Affected
                opensuse
- factory
- cscreen
CWE
                
                    
                        
                        CWE-732
                        
            Incorrect Permission Assignment for Critical Resource
