CVE-2021-41387

EUVD-2021-28415
seatd-launch in seatd 0.6.x before 0.6.2 allows privilege escalation because it uses execlp and may be installed setuid root.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
Affected Products (NVD)
VendorProductVersion
seatd_projectseatd
0.6.0 ≤
𝑥
< 0.6.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
seatd
bookworm
0.7.0-6
fixed
sid
0.9.1-1
fixed
trixie
0.9.1-1
fixed