Vulnerability Description
USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Usbview Project | Usbview | < 2.2 |
| Canonical | Ubuntu Linux | - |
| Debian | Debian Linux | - |
| Gentoo | Linux | - |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2022/01/22/1Mailing ListThird Party Advisory
- https://github.com/gregkh/usbview/commit/bf374fa4e5b9a756789dfd88efa93806a395463PatchThird Party Advisory
- https://security.gentoo.org/glsa/202310-15Third Party Advisory
- https://www.debian.org/security/2022/dsa-5052Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/01/21/1ExploitMailing ListPatch
- http://www.openwall.com/lists/oss-security/2022/01/22/1Mailing ListThird Party Advisory
- https://github.com/gregkh/usbview/commit/bf374fa4e5b9a756789dfd88efa93806a395463PatchThird Party Advisory
- https://security.gentoo.org/glsa/202310-15Third Party Advisory
- https://www.debian.org/security/2022/dsa-5052Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/01/21/1ExploitMailing ListPatch
FAQ
What is CVE-2022-23220?
CVE-2022-23220 is a vulnerability with a CVSS score of 7.8 (HIGH). USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authenticat...
How severe is CVE-2022-23220?
CVE-2022-23220 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23220?
Check the references section above for vendor advisories and patch information. Affected products include: Usbview Project Usbview, Canonical Ubuntu Linux, Debian Debian Linux, Gentoo Linux.