CVE Vulnerabilities

CVE-2017-20148

Published: Sep 20, 2022 | Modified: Oct 01, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
LOW

In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck user because of insecure recursive chown calls.

Affected Software

Name Vendor Start Version End Version
Logcheck Debian * 1.3.23 (including)
Logcheck Ubuntu bionic *
Logcheck Ubuntu kinetic *
Logcheck Ubuntu lunar *
Logcheck Ubuntu mantic *
Logcheck Ubuntu trusty *
Logcheck Ubuntu xenial *

References