CVE-2021-36781 MEDIUM

CVE-2021-36781: parsec: dangerous 777 permissions for /run/parsec

Vendor Opensuse
Product Factory
Weakness CWE-276
Published January 14, 2022
Last update September 16, 2024

CVSS base score

5.9/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0.8.1-1.1.

Key dates

02Disclosure timeline

January 14, 2022 CVE published
September 16, 2024 Record updated