We found results for “”
WS-2023-0328
Date: October 3, 2023
The crate please is vulnerable to privilege escalation using ioctls TIOCSTI and TIOCLINUX on systems where they are not disabled. This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges.
Language: RUST
Severity Score
Severity Score
Weakness Type (CWE)
Improper Privilege Management
CWE-269CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | LOW |
Availability (A): | NONE |