CVE Vulnerabilities

CVE-2023-46277

Published: Oct 20, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.)

Affected Software

NameVendorStart VersionEnd Version
PleaseEdneville*0.5.4 (including)
Rust-pleaserUbuntubionic*
Rust-pleaserUbuntulunar*
Rust-pleaserUbuntumantic*
Rust-pleaserUbuntuoracular*
Rust-pleaserUbuntuplucky*
Rust-pleaserUbuntutrusty*
Rust-pleaserUbuntuxenial*

References