Vulnerability Summary for the Week of September 4, 2023

 

High Vulnerabilities

Primary
Vendor — Product
Description Published CVSS Score Source & Patch Info
canonical_ltd. — snapd_for_linux Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected – this can only be exploited when snaps are run on a virtual console. 2023-09-01 10 CVE-2023-1523
MISC
MISC
MISC
MISC
bmc — server_automation BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass. 2023-09-05 9.8 CVE-2017-9453
This article has been indexed from Bulletins

Read the original article:

Tags: