In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileges. There is a race condition involving /var/lib/smokeping and chown.
References
Link | Resource |
---|---|
https://bugs.gentoo.org/602652 | Exploit Issue Tracking Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-09-20T17:01:47
Updated: 2022-09-20T18:13:57
Reserved: 2022-09-20T00:00:00
Link: CVE-2016-20015
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-09-20T18:15:09.897
Modified: 2022-09-22T00:19:34.010
Link: CVE-2016-20015
JSON object: View
Redhat Information
No data.
CWE