CVE
- Id
- 87657
- CVE No.
- CVE-2016-10151
- Status
- Candidate
- Description
- The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID with UID to determine whether to use configurations from environment variables, which allows local users to gain privileges via the (1) HESIOD_CONFIG or (2) HES_DOMAIN environment variable and leveraging certain SUID/SGUID binary.
- Phase
- Assigned (20170120)
- Votes
- None (candidate not yet proposed)
- Comments