CVE-2008-5397
EPSS 0.36%
描述
Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.
如何修補 CVE-2008-5397
要修補 CVE-2008-5397,請將受影響套件升級到下列已修補版本。
- Debian/tor—升級至 0.2.0.32-1 或更新版本
CVE-2008-5397 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 0.2.0.32-1