// For flags

CVE-2021-31523

 

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/sonar file, which allows local users to gain privileges because this is arguably incompatible with the design of the Mesa 3D Graphics library dependency.

El paquete Debian xscreensaver versión 5.42+dfsg1-1 para XScreenSaver presenta la función cap_net_raw habilitado para el archivo /usr/libexec/xscreensaver/sonar, lo que permite a usuarios locales alcanzar privilegios porque podría decirse que esto es incompatible con el diseño de la dependencia de la biblioteca Mesa 3D Graphics

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-04-21 CVE Reserved
  • 2021-04-21 CVE Published
  • 2024-08-03 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-269: Improper Privilege Management
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Xscreensaver Project
Search vendor "Xscreensaver Project"
Xscreensaver
Search vendor "Xscreensaver Project" for product "Xscreensaver"
5.42\+dfsg1-1
Search vendor "Xscreensaver Project" for product "Xscreensaver" and version "5.42\+dfsg1-1"
-
Affected