← Back

CVE-2022-21946

nvd nist
Published: Mar 16, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Exploitability: 1.8 / Impact: 3.4
Source: NVD

Description

A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local users to gain the privileges of the tty and dialout groups and access and manipulate any running cscreen seesion. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.

Affected (1)

Products: Opensuse: Cscreen
1 product
Cscreen
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1.2 to 1.3
Running on/withPlatform Versions
Opensuse
Factory
All versions

References (2)

Source: meissner@suse.de
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory

Timeline

No history available yet.