cb
cvebase
.
~
/
products
/
debian
/
tmpreaper
Search CVEs, products, detections…
⌘K
pipeline live
Digest
Docs
Home
/
Products
/
debian
/
Debian Tmpreaper
Debian Tmpreaper vulnerabilities
1 known vulnerability affecting
debian/tmpreaper
.
Track
Version
All versions
Total CVEs
1
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH
1
Vulnerabilities
Sort
Most important
Highest Priority
Highest EPSS
Highest CVSS
Newest
Oldest
Page 1 of 1
CVE-2019-3461
P4
HIGH
CVSS 7.0
v1.6.13\+nmu1
2019-02-04
CVE-2019-3461 [HIGH] CWE-362 CVE-2019-3461: Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() whi Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mounting via rename() could potentially lead to a file being placed elsewhereon the filesystem hierarchy (e.g. /etc/cron.d/) if the directory being cleaned up was on the same physical filesystem. Fixed versio
nvd
osv
debian
Debian Tmpreaper vulnerabilities | cvebase