CVE-2023-40303

GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:inetutils:*:*:*:*:*:*:*:*

History

02 Jan 2024, 01:15

Type Values Removed Values Added
Summary GNU inetutils through 2.4 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process. GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.

31 Dec 2023, 00:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2023/12/30/4 -
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00013.html -

21 Aug 2023, 14:24

Type Values Removed Values Added
CWE CWE-252
CPE cpe:2.3:a:gnu:inetutils:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References (MISC) https://lists.gnu.org/archive/html/bug-inetutils/2023-07/msg00000.html - (MISC) https://lists.gnu.org/archive/html/bug-inetutils/2023-07/msg00000.html - Exploit, Mailing List, Patch, Vendor Advisory
References (MISC) https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=e4e65c03f4c11292a3e40ef72ca3f194c8bffdd6 - (MISC) https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=e4e65c03f4c11292a3e40ef72ca3f194c8bffdd6 - Patch
References (MISC) https://ftp.gnu.org/gnu/inetutils/ - (MISC) https://ftp.gnu.org/gnu/inetutils/ - Product

14 Aug 2023, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-14 05:15

Updated : 2024-02-05 00:01


NVD link : CVE-2023-40303

Mitre link : CVE-2023-40303

CVE.ORG link : CVE-2023-40303


JSON object : View

Products Affected

gnu

  • inetutils
CWE
CWE-252

Unchecked Return Value