Improper Privilege Management
Affecting mailutils package, versions <1:3.5-4
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
References
CVSS Score
7.8
high severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2019-18862
- Snyk ID
- SNYK-DEBIAN10-MAILUTILS-483076
- Disclosed
- 11 Nov, 2019
- Published
- 11 Nov, 2019