seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The attack vector is a user-supplied socket pathname. (CVSS:9.3) (Last Update:2022-03-04)
http://dlvr.it/SL64gK
Friday, March 4, 2022
Subscribe to:
Post Comments (Atom)
Black swans events are shaping the cybersecurity present and future - VentureBeat
Black swans events are shaping the cybersecurity present and future VentureBeat http://dlvr.it/ShfHB2

-
Laravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution via an unserialize pop chain in __...
-
TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This v...
-
Cybersecurity quarterly benchmarks: Q1, 2022 Cybersecurity Dive http://dlvr.it/SPdcjS
No comments:
Post a Comment