Vulnerability CVE-2022-37706


Published: 2022-12-25

Description:
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/.. substring.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Ubuntu 22.04.1 X64 Desktop Enlightenment 0.25.3-1 Privilege Escalation
h00die
05.10.2022
Med.
Enlightenment 0.25.3 Privilege Escalation
nu11secur1ty
27.12.2022

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

 References:
https://github.com/MaherAzzouzi/CVE-2022-37706-LPE-exploit
https://git.enlightenment.org/enlightenment/enlightenment/commit/cae78cbb169f237862faef123e4abaf63a1f5064
https://git.enlightenment.org/enlightenment/enlightenment/commit/cc7faeccf77fef8b0ae70e312a21e4cde087e141

Copyright 2024, cxsecurity.com

 

Back to Top