VDB

CVE-2020-36394

CVE-2020-36394 REJECTED CVSS 7 HIGH

pam_setquota.c in the pam_setquota module before 2020-05-29 for Linux-PAM allows local attackers to set their quota on an arbitrary filesystem, in certain situations where the attacker's home directory is a FUSE filesystem mounted under /home.

EPSS 0.35% · 27.3th percentile

Risk Scores

CVSS 3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.35%
27.3th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSpam0, 1.3.1-5ubuntu11, 1.4.0-10ubuntu1

Timeline

  • Jun 22, 2021 CVE Published
  • Jun 23, 2021 EPSS Score
  • Aug 22, 2021 EPSS Score
  • Oct 22, 2021 EPSS Score
  • Dec 21, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 21, 2022 EPSS Score
  • Jun 21, 2022 EPSS Score
  • Aug 21, 2022 EPSS Score
  • Oct 21, 2022 EPSS Score
  • Dec 20, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›