CVE-2025-59378 - CERT CVE
ID CVE-2025-59378
Sažetak In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
Reference
CVSS
Base: 5.7
Impact: 2.7
Exploitability:2.5
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW NONE
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Zadnje važnije ažuriranje 15-09-2025 - 15:21
Objavljeno 15-09-2025 - 06:15