CVE-2021-43414: High severity gnu hurd vulnerability
Published Nov 7, 2021
·Updated
An issue was discovered in GNU Hurd before 0.9 20210404-9. The use of an authentication protocol in the proc server is vulnerable to man-in-the-middle attacks, which can be exploited for local privilege escalation to get full root access.
Affected Software
1 affected component
GNU Hurd<0.9.20210404-9
Event History
Nov 7, 2021
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-43414?
CVE-2021-43414 is classified as a high severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2021-43414?
To mitigate CVE-2021-43414, upgrade to GNU Hurd version 0.9.20210404-9 or later.
3
What type of attack does CVE-2021-43414 expose the system to?
CVE-2021-43414 exposes the system to man-in-the-middle attacks.
4
What can attackers achieve by exploiting CVE-2021-43414?
By exploiting CVE-2021-43414, attackers can gain full root access to the affected system.
5
Which versions of GNU Hurd are affected by CVE-2021-43414?
GNU Hurd versions prior to 0.9.20210404-9 are affected by CVE-2021-43414.