CVE-2019-15900
Summary
| CVE | CVE-2019-15900 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-18 16:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. Instead, the uninitialized variable errstr was checked and in some cases returned success even if sscanf failed. The result was that, instead of reporting that the supplied username or group name did not exist, it would execute the command as root. |
Risk And Classification
Problem Types: CWE-754 | CWE-863 | CWE-908
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Doas Project | Doas | All | All | All | All |
| Application | Doas Project | Doas | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Added optimization to Makefile (can be set/overruled using OPT). · slicer69/doas@2f83222 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Comparing 6.1p1...6.2 · slicer69/doas · GitHub | MISC | github.com | Release Notes, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.