Duncan Overbruck

2 exploits Active since Oct 2019
CVE-2019-15901 WRITEUP HIGH WRITEUP
slicer69 doas <6.2 - Privilege Escalation
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. A setusercontext(3) call with flags to change the UID, primary GID, and secondary GIDs was replaced (on certain platforms: Linux and possibly NetBSD) with a single setuid(2) call. This resulted in neither changing the group id nor initializing secondary group ids.
CVSS 8.8
CVE-2019-25016 WRITEUP HIGH WRITEUP
OpenDoas <6.9 - Privilege Escalation
In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user to execute specific commands were not affected by this issue.
CVSS 8.8