CVE ID | CVE-2020-15704 |
CVSS SCORE | 5.5, AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
AFFECTED VENDORS |
Canonical |
AFFECTED PRODUCTS |
Ubuntu |
VULNERABILITY DETAILS |
This vulnerability allows local attackers to read arbitrary files on affected installations of Canonical Ubuntu. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of environment variables in pppd. The issue results from the lack of proper validation of user-supplied data, which can allow the read of arbitrary files. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. |
ADDITIONAL DETAILS |
https://ubuntu.com/security/notices/USN-4451-1 |
DISCLOSURE TIMELINE |
|
CREDIT | Thomas Chauchefoin (@swapgs) from Synacktiv (@Synacktiv) |