seatd-launch in seatd 0.6.x before 0.6.4 allows removing...
Critical severity
Unreviewed
Published
Feb 25, 2022
to the GitHub Advisory Database
•
Updated Nov 9, 2023
Description
Published by the National Vulnerability Database
Feb 24, 2022
Published to the GitHub Advisory Database
Feb 25, 2022
Last updated
Nov 9, 2023
seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The attack vector is a user-supplied socket pathname.
References