stable

rust-below-0.9.0-1.el8

FEDORA-EPEL-2025-ae12e02519 created by salimma 7 months ago for Fedora EPEL 8

A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.

https://www.cve.org/CVERecord?id=CVE-2025-27591 https://github.com/facebookincubator/below/security/advisories/GHSA-9mc5-7qhg-fp3w

This update has been submitted for testing by salimma.

7 months ago

This update's test gating status has been changed to 'ignored'.

7 months ago

This update has been pushed to testing.

7 months ago

This update has been submitted for stable by bodhi.

7 months ago

This update has been pushed to stable.

7 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
1
Stable by Time
7 days
Dates
submitted
7 months ago
in testing
7 months ago
in stable
7 months ago
approved
7 months ago
BZ#2351589 CVE-2025-27591 rust-below: Privilege Escalation in Below via World-Writable Directory [epel-8]
0
0

Automated Test Results