UBUNTU-CVE-2023-40303
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-40303
UBUNTU-CVE-2023-40303
Summary:
Details: GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
References: https://ubuntu.com/security/CVE-2023-40303, https://lists.gnu.org/archive/html/bug-inetutils/2023-07/msg00000.html, https://ftp.gnu.org/gnu/inetutils/, https://ubuntu.com/security/notices/USN-6304-1, https://www.cve.org/CVERecord?id=CVE-2023-40303, https://ubuntu.com/security/notices/USN-7781-1
Affected packages
Package
Name: inetutils
Purl: pkg:deb/ubuntu/inetutils@2:1.9.2-1ubuntu0.1~esm2?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
