HIGH
Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tenshi.pid modification before a root script executes a "kill `cat /pathname/tenshi.pid`" command
Published Jul 30, 2017
7.5
HIGHCVSS 3.0
EPSS 1.09%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.