su
by OpenBSD
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-19519 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2019 | In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c. | ||
| CVE-1999-0845 | 0.03 | — | 0.01 | Nov 25, 1999 | Buffer overflow in SCO su program allows local users to gain root access via a long username. | |||
| CVE-2000-0996 | 0.00 | — | 0.01 | Dec 19, 2000 | Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell. |
- risk 0.51cvss 7.8epss 0.00
In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.
- CVE-1999-0845Nov 25, 1999risk 0.03cvss —epss 0.01
Buffer overflow in SCO su program allows local users to gain root access via a long username.
- CVE-2000-0996Dec 19, 2000risk 0.00cvss —epss 0.01
Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.