Improper authorization control for web services In util-linux
Description
script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 2.11n-1 | ||
debian 14 | 2.11n-1 | ||
debian 13 | 2.11n-1 | ||
debian 12 | 2.11n-1 |
Aliases
1. 2. 3. 4. 5.