CVE-2021-31523
The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/sonar file, which allows local users to gain privileges because this is arguably incompatible with the design of the Mesa 3D Graphics…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/sonar file, which allows local users to gain privileges because this is arguably incompatible with the design of the Mesa 3D Graphics library dependency.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- xscreensaver project/xscreensaver
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2021/04/21/3Mailing List, Patch, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/04/17/1Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/04/21/3Mailing List, Patch, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/04/17/1Mailing List, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.