CVE-2021-41387

seatd-launch in seatd 0.6.x before 0.6.2 allows privilege escalation because it uses execlp and may be installed setuid root.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
VendorProductVersion
seatd_projectseatd
0.6.0 ≤
𝑥
< 0.6.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
seatd
bookworm
0.7.0-6
fixed
sid
0.9.1-1
fixed
trixie
0.9.1-1
fixed