CVE-2020-21583

EUVD-2020-14351
An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
Affected Products (NVD)
VendorProductVersion
kernelutil-linux
𝑥
< 2.27
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
util-linux
bookworm
2.38.1-5+deb12u1
fixed
bookworm (security)
2.38.1-5+deb12u1
fixed
bullseye
2.36.1-8+deb11u2
fixed
bullseye (security)
2.36.1-8+deb11u2
fixed
sid
2.40.2-10
fixed
trixie
2.40.2-9
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
util-linux
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
needed
xenial
not-affected