GNU inetutils through 2.4 may allow privilege escalation...
High severity
Unreviewed
Published
Aug 14, 2023
to the GitHub Advisory Database
•
Updated Jan 2, 2024
Description
Published by the National Vulnerability Database
Aug 14, 2023
Published to the GitHub Advisory Database
Aug 14, 2023
Last updated
Jan 2, 2024
GNU inetutils through 2.4 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
References