CVE-2022-23220

EUVD-2022-28309
USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
Affected Products (NVD)
VendorProductVersion
usbview_projectusbview
𝑥
< 2.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
usbview
bookworm
3.0-3
fixed
bullseye
2.0-21-g6fe2f4f-2+deb11u1
fixed
bullseye (security)
2.0-21-g6fe2f4f-2+deb11u1
fixed
sid
3.1-1
fixed
stretch
not-affected
trixie
3.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
usbview
bionic
Fixed 2.0-21-g6fe2f4f-1ubuntu1.1
released
focal
Fixed 2.0-21-g6fe2f4f-2ubuntu0.20.04.1
released
hirsute
ignored
impish
Fixed 2.0-21-g6fe2f4f-2ubuntu0.21.10.3
released
jammy
Fixed 2.0-21-g6fe2f4f-2ubuntu1
released
kinetic
not-affected
lunar
not-affected
xenial
not-affected