A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Backports SLE-15-SP3 canna versions prior to canna-3.7p3-bp153.2.3.1. openSUSE Backports SLE-15-SP4 canna versions prior to 3.7p3-bp154.3.3.1. openSUSE Factory was also affected. Instead of fixing the package it was deleted there.
📦
canna
Vendor: canna
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
0
Remote Access
Total CVEs
4
Total Indexed
Avg. EPSS
0.84%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
5.3
CVSS
Severity: MEDIUM
7.2
CVSS
Buffer overflow in the irw_through function for Canna 3.5b2 and earlier allows local users to execute arbitrary code as the bin user.
Severity: HIGH
6.4
CVSS
Canna 3.6 and earlier does not properly validate requests, which allows remote attackers to cause a denial of service or information leak.
Severity: MEDIUM