We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6714



Assignercanonical
Reserved2024-07-12
Published2024-07-23
Updated2024-08-01

Description

An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.



HIGH: 8.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-73

Product status

Any version before 0.1.5
affected

Credits

James Henstridge 0x40089fd3f0

Matthew Gary Hagemann 0x40089fd400

Luci Stanescu 0x40089fd410

References

https://github.com/canonical/ubuntu-desktop-provision/commit/8d9086de0f82894ff27a9e429ff4f45231020092 patch

https://bugs.launchpad.net/ubuntu/+source/provd/+bug/2071574 issue-tracking

https://www.cve.org/CVERecord?id=CVE-2024-6714 issue-tracking

cve.org CVE-2024-6714

nvd.nist.gov CVE-2024-6714

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.