CVE-2021-36781

Severity
4.4MEDIUM
EPSS
0.0%
top 90.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 14
Latest updateJan 15

Description

A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0.8.1-1.1.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 2.5 | Impact: 3.4

Affected Packages2 packages

CVEListV5opensuse/factoryparsec0.8.1-1.1
NVDopensuse/factory< 0.8.1-1.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m398-vv9j-2r7f: A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS o2022-01-15
CVEList
parsec: dangerous 777 permissions for /run/parsec2022-01-14
CVE-2021-36781 (MEDIUM CVSS 4.4) | A Incorrect Default Permissions vul | cvebase.io