Openrc
Openrc Project · 2 CVEs
CVE-2021-42341
HIGH
checkpath in OpenRC before 0.44.7 uses the direct output of strlen() to allocate strings, which does not account for th…
Oct 14, 2021
CVE-2018-21269
MEDIUM
checkpath in OpenRC through 0.42.1 might allow local users to take ownership of arbitrary files because a non-terminal…
Oct 27, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2021-42341 | checkpath in OpenRC before 0.44.7 uses the direct output of strlen() to allocate strings, which does not account for the '\0' byte at the end of the string. Th… | HIGH | 2.12% | Oct 14, 2021 |
| CVE-2018-21269 | checkpath in OpenRC through 0.42.1 might allow local users to take ownership of arbitrary files because a non-terminal path component can be a symlink. | MEDIUM | 0.39% | Oct 27, 2020 |
Showing 1 to 2 of 2 CVEs