pleaser
Activity
- Latest release
- 2y ago
- Total releases
- 33
- Cadence
- ~10 days
- Last 12 months
- 0
Details
- License
- GPL-3.0-or-later
- First release
- Aug 23, 2020
| Version | Released | |
|---|---|---|
0.5.6
unknown
|
0.5.6
unknown
Dependencies (10)
+ 2 more |
|
0.5.5
unknown
|
0.5.5
unknown
Dependencies (10)
+ 2 more |
|
0.5.4
unknown
1 CVE
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev |
0.5.4
unknown
Dependencies (10)
+ 2 more |
|
0.5.3
unknown
1 CVE
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev |
0.5.3
unknown
Dependencies (10)
+ 2 more |
|
0.5.2
unknown
1 CVE
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev |
0.5.2
unknown
Dependencies (10)
+ 2 more |
|
0.5.1
unknown
1 CVE
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev |
0.5.1
unknown
Dependencies (10)
+ 2 more |
|
0.5.0
unknown
1 CVE
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev |
0.5.0
unknown
Dependencies (10)
+ 2 more |
|
0.4.2
unknown
1 CVE
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev |
0.4.2
unknown
Dependencies (10)
+ 2 more |
|
0.4.1
unknown
1 CVE
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev |
0.4.1
unknown
Dependencies (10)
+ 2 more |
|
0.4.0
unknown
1 CVE
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev |
0.4.0
unknown
Dependencies (10)
+ 2 more |
|
0.3.25
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.25
unknown
Dependencies (9)
+ 1 more |
|
0.3.24
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.24
unknown
Dependencies (9)
+ 1 more |
|
0.3.22
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.22
unknown
Dependencies (9)
+ 1 more |
|
0.3.21
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.21
unknown
Dependencies (9)
+ 1 more |
|
0.3.20
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.20
unknown
Dependencies (9)
+ 1 more |
|
0.3.19
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.19
unknown
Dependencies (9)
+ 1 more |
|
0.3.18
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.18
unknown
Dependencies (9)
+ 1 more |
|
0.3.17
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.17
unknown
Dependencies (9)
+ 1 more |
|
0.3.16
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.16
unknown
Dependencies (9)
+ 1 more |
|
0.3.15
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.15
unknown
Dependencies (9)
+ 1 more |
|
0.3.12
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.12
unknown
Dependencies (9)
+ 1 more |
|
0.3.11
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.11
unknown
Dependencies (9)
+ 1 more |
|
0.3.10
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.10
unknown
Dependencies (9)
+ 1 more |
|
0.3.9
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.9
unknown
Dependencies (9)
+ 1 more |
|
0.3.8
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.8
unknown
Dependencies (9)
+ 1 more |
|
0.3.7
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.7
unknown
Dependencies (9)
+ 1 more |
|
0.3.5
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.5
unknown
Dependencies (9)
+ 1 more |
|
0.3.4
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.4
unknown
Dependencies (10)
+ 2 more |
|
0.3.3
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.3
unknown
Dependencies (10)
+ 2 more |
|
0.3.1
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.1
unknown
Dependencies (10)
+ 2 more |
|
0.3.0
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.0
unknown
Dependencies (10)
+ 2 more |
|
0.2.0
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.2.0
unknown
Dependencies (9)
+ 1 more |
|
0.1.0
unknown
4 CVEs
CVE-2023-46277
GHSA-cgf8-h3fp-h956
RUSTSEC-2023-0066
Oct 20, 2023
Pleaser privilege escalation vulnerability
High
Local
Low
Low
None
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) Here is how to see it in action:
Please note that: This affects both the case where root wants to drop privileges as well when non-root wants to gain other privileges. References
Updated Sep 12, 2024 · Source: OSV.dev
CVE-2021-31155
GHSA-vc5p-j8vw-mc6x
RUSTSEC-2021-0101
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31154
GHSA-pp74-39w2-v4w9
RUSTSEC-2021-0102
Aug 25, 2021
Permissions bypass in pleaser
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-31153
GHSA-f3fg-5j9p-vchc
RUSTSEC-2021-0104
Aug 25, 2021
File exposure in pleaser
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. Fixed in
0.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.0
unknown
Dependencies (9)
+ 1 more |