CVE Vulnerabilities

CVE-2022-37706

Improper Privilege Management

Published: Dec 25, 2022 | Modified: Jan 04, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/.. substring.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Enlightenment Enlightenment * 0.25.4 (excluding)
E17 Ubuntu bionic *
E17 Ubuntu kinetic *
E17 Ubuntu lunar *
E17 Ubuntu mantic *
E17 Ubuntu trusty *
E17 Ubuntu xenial *

Potential Mitigations

References