Vulnerability Description
The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/sonar file, which allows local users to gain privileges because this is arguably incompatible with the design of the Mesa 3D Graphics library dependency.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xscreensaver Project | Xscreensaver | 5.42\+dfsg1-1 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2021/04/21/3Mailing ListPatchThird Party Advisory
- https://www.openwall.com/lists/oss-security/2021/04/17/1Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/04/21/3Mailing ListPatchThird Party Advisory
- https://www.openwall.com/lists/oss-security/2021/04/17/1Mailing ListPatchThird Party Advisory
FAQ
What is CVE-2021-31523?
CVE-2021-31523 is a vulnerability with a CVSS score of 7.8 (HIGH). The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/sonar file, which allows local users to gain privileges because this is arguably...
How severe is CVE-2021-31523?
CVE-2021-31523 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31523?
Check the references section above for vendor advisories and patch information. Affected products include: Xscreensaver Project Xscreensaver.