bugzilla.suse.com
https://bugzilla.suse.com/show_bug.cgi?id=1196451 CVE-2022-21946
MEDIUM
suddoers configuration for cscreen not restrictive enough
Record summary
CVE-2022-21946 has a selected CVSS score of 5.3 (medium).
Description
A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local users to gain the privileges of the tty and dialout groups and access and manipulate any running cscreen seesion. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FactoryBrowse openSUSE / Factory | CVE List | cscreen to ≤ 1.2-1.3 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-21946