Jan. 26, 2023, 9:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

uptimed before 0.4.6-r1 on Gentoo allows local users (with access to the uptimed user account) to gain root privileges by creating a hard link within the /var/spool/uptimed directory, because there is an unsafe chown -R call.

access account call cve directory gentoo hard link local privileges root var

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Penetration Testing Manager, Proactive Security

@ Amazon.com | US, Virtual

Cryptographic Engineer - Midnight

@ IO Global | United Kingdom - Remote

Application Security Intern - Southeast (Remote)

@ GuidePoint Security LLC | Remote