CVE-2023-40303

GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:inetutils:*:*:*:*:*:*:*:*

History

02 Jan 2024, 01:15

Type Values Removed Values Added
Summary (en) GNU inetutils through 2.4 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process. (en) GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.

31 Dec 2023, 00:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2023/12/30/4 -

08 Oct 2023, 14:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00013.html -

21 Aug 2023, 14:24

Type Values Removed Values Added
First Time Gnu inetutils
Gnu
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-252
CPE cpe:2.3:a:gnu:inetutils:*:*:*:*:*:*:*:*
References (MISC) https://ftp.gnu.org/gnu/inetutils/ - (MISC) https://ftp.gnu.org/gnu/inetutils/ - Product
References (MISC) https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=e4e65c03f4c11292a3e40ef72ca3f194c8bffdd6 - (MISC) https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=e4e65c03f4c11292a3e40ef72ca3f194c8bffdd6 - Patch
References (MISC) https://lists.gnu.org/archive/html/bug-inetutils/2023-07/msg00000.html - (MISC) https://lists.gnu.org/archive/html/bug-inetutils/2023-07/msg00000.html - Exploit, Mailing List, Patch, Vendor Advisory

14 Aug 2023, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-14 05:15

Updated : 2024-01-02 01:15


NVD link : CVE-2023-40303

Mitre link : CVE-2023-40303

CVE.ORG link : CVE-2023-40303


JSON object : View

Products Affected

gnu

  • inetutils
CWE
CWE-252

Unchecked Return Value