Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a remote authenticated attacker to retain elevated privileges under error conditions.
Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a remote authenticated attacker to retain elevated privileges under error conditions.
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度 | 50.00 |
| 利用信号(无额外利用信号) | ×1.00 |
| VPI | 50.00 |
VPI 公式 vpi-v1