VDB
CVE-2022-2787
CVE-2022-2787
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.
EPSS 0.34% · 57.2th percentile
Risk Scores
CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.34%
57.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | schroot | unspecified |
| debian | schroot | 0 |
| debian | debian_linux | 10.0, 11.0 |
Timeline
- Aug 27, 2022 CVE Published
- Aug 28, 2022 EPSS Score
- Oct 13, 2022 EPSS Score
- Nov 27, 2022 EPSS Score
- Jan 12, 2023 EPSS Score
- Feb 26, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 13, 2023 EPSS Score
- May 28, 2023 EPSS Score
- Jul 13, 2023 EPSS Score
- Aug 27, 2023 EPSS Score
- Oct 12, 2023 EPSS Score
References
- https://codeberg.org/shelter/reschroot/commit/6f7166a285e1e97aea390be633591f9791b29a6d url
- https://lists.debian.org/debian-security-announce/2022/msg00182.html url
- https://lists.debian.org/debian-lts-announce/2022/08/msg00007.html url
- GLSA-202210-11 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2787 advisory