CVE-2022-2787
Summary
| CVE | CVE-2022-2787 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-27 12:15:00 UTC |
| Updated | 2022-11-16 20:06:00 UTC |
| Description | Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| schroot: Denial of Service (GLSA 202210-11) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Have stricter rules on chroot names [CVE-2022-2787] · 6f7166a285 - reschroot - Codeberg.org |
MISC |
codeberg.org |
|
| [SECURITY] [DLA 3075-1] schroot security update |
MISC |
lists.debian.org |
|
| [SECURITY] [DSA 5213-1] schroot security update |
MISC |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180948 Debian Security Update for schroot (DLA 3075-1)
- 180950 Debian Security Update for schroot (DSA 5213-1)
- 198913 Ubuntu Security Notification for Schroot Vulnerability (USN-5584-1)
- 710645 Gentoo Linux schroot Denial of Service Vulnerability (GLSA 202210-11)