2 results (0.021 seconds)

CVSS: 7.2EPSS: 0%CPEs: 2EXPL: 0

vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=360438 http://www.securityfocus.com/bid/17361 https://savannah.nongnu.org/bugs/?func=detailitem&item_id=15996 https://savannah.nongnu.org/patch/?func=detailitem&item_id=4966 •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could allow local users to conduct unauthorized activities. • http://secunia.com/advisories/19333 http://secunia.com/advisories/19339 http://www.debian.org/security/2006/dsa-1011 http://www.securityfocus.com/bid/17180 https://exchange.xforce.ibmcloud.com/vulnerabilities/25407 •