Logo
vulnerabilityCVE-2023-40303
Name
CVE-2023-40303
Source
NVD ( link)Debian ( link)
Description
GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
inetutils
Patched

Vulnerability Rating#


7.8
CVSSv31

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
2.7
Not Affected
yocto
scarthgap
2.5
Not Affected

Resolved with patches#


inetutils (yocto:kirkstone)

#
Title
Author
Resolve
1
CVE-2023-40303: ftpd,rcp,rlogin,rsh,rshd,uucpd: fix: check
Jeffrey Bencteux <jeffbencteux@gmail.com>
CVE-2023-40303
2
CVE-2023-40303: Indent changes in previous commit.
Simon Josefsson <simon@josefsson.org>
CVE-2023-40303