7.8

CVE-2016-2568

pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.268
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.1 6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
NIST 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
CWE-116 Improper Encoding or Escaping of Output

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

http://www.openwall.com/lists/oss-security/2016/02/26/3
Third Party Advisory
Mailing List
https://access.redhat.com/security/cve/cve-2016-2568
Third Party Advisory
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=816062
Third Party Advisory
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=1300746
Third Party Advisory
Issue Tracking
https://ubuntu.com/security/CVE-2016-2568
Third Party Advisory