CVE Vulnerabilities

CVE-2022-2787

Improper Preservation of Permissions

Published: Aug 27, 2022 | Modified: Nov 16, 2022
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

Name Vendor Start Version End Version
Schroot Debian * 1.6.13 (excluding)
Debian_linux Debian 10.0 (including) 10.0 (including)
Debian_linux Debian 11.0 (including) 11.0 (including)

References