VYPR

su

by OpenBSD

CVEs (3)

  • CVE-2019-19519HigDec 5, 2019
    risk 0.51cvss 7.8epss 0.00

    In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.

  • CVE-1999-0845Nov 25, 1999
    risk 0.03cvss epss 0.01

    Buffer overflow in SCO su program allows local users to gain root access via a long username.

  • CVE-2000-0996Dec 19, 2000
    risk 0.00cvss epss 0.01

    Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.