CVE-2019-15900 Information
Feb 14, 2021
cve
Description
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3) sscanf was used without checking for error cases. Instead the uninitialized variable errstr was checked and in some cases returned success even if sscanf failed. The result was that instead of reporting that the supplied username or group name did not exist it would execute the command as root.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/slicer69/doas/commit/2f83222829448e5bc4c9391d607ec265a1e06531 https://github.com/slicer69/doas/compare/6.1p1…6.2
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: