CVE Vulnerabilities

CVE-2022-2787

Improper Preservation of Permissions

Published: Aug 27, 2022 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

NameVendorStart VersionEnd Version
SchrootDebian*1.6.13 (excluding)
Debian_linuxDebian10.0 (including)10.0 (including)
Debian_linuxDebian11.0 (including)11.0 (including)
SchrootUbuntubionic*
SchrootUbuntuesm-infra/bionic*
SchrootUbuntuesm-infra/focal*
SchrootUbuntuesm-infra/xenial*
SchrootUbuntufocal*
SchrootUbuntujammy*
SchrootUbuntutrusty*
SchrootUbuntuupstream*
SchrootUbuntuxenial*

References