PT-2022-4293 · Debian+2 · Schroot+2

·

CVE-2022-2787

·

Published

2022-08-15

·

Updated

2022-11-16

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions schroot versions prior to 1.6.13
Description The issue is related to insufficient access control in the schroot package of Debian GNU/Linux, which can be exploited to cause a denial of service. This affects the schroot service for all users who may start a schroot session.
Recommendations For versions prior to 1.6.13, update to version 1.6.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the schroot service to minimize the risk of exploitation.

Fix

DoS

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05147
CVE-2022-2787
DLA-3075-1
DSA-5213-1
MGASA-2022-0329
USN-5584-1

Affected Products

Linuxmint
Ubuntu
Schroot