CVE-2022-29799: Path Traversal
A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base directory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29799?
CVE-2022-29799 is rated as a high severity vulnerability due to its potential for directory traversal and exploitation.
How do I fix CVE-2022-29799?
To fix CVE-2022-29799, ensure that networkd-dispatcher is updated to a patched version that properly sanitizes inputs.
Which software is affected by CVE-2022-29799?
CVE-2022-29799 affects Microsoft Windows Defender for Endpoint on Linux.
What type of attack can exploit CVE-2022-29799?
CVE-2022-29799 can be exploited through a directory traversal attack that allows escaping the 'etc/networkd-dispatcher' directory.
Is there a workaround for CVE-2022-29799?
A temporary workaround for CVE-2022-29799 involves limiting the permissions or access to the affected directory until a patch is applied.