CVE-2023-40303: High severity GNU InetUtils vulnerability
GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of setid() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
Other sources
GNU inetutils through 2.4 may allow privilege escalation because of unchecked return values of setid() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-40303?
CVE-2023-40303 is a vulnerability in GNU inetutils through 2.4 that may allow privilege escalation due to unchecked return values of certain functions.
How severe is CVE-2023-40303?
CVE-2023-40303 has a severity rating of 7.8 out of 10, which is considered high.
Which software versions are affected by CVE-2023-40303?
Versions up to and including GNU inetutils 2.4 are affected by CVE-2023-40303.
How can I fix CVE-2023-40303 on Debian?
To fix CVE-2023-40303 on Debian, you should update the inetutils package to version 2:2.4-3 or higher.
Where can I find more information about CVE-2023-40303?
More information about CVE-2023-40303 can be found at the following references: [https://ftp.gnu.org/gnu/inetutils/](https://ftp.gnu.org/gnu/inetutils/), [https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=e4e65c03f4c11292a3e40ef72ca3f194c8bffdd6](https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=e4e65c03f4c11292a3e40ef72ca3f194c8bffdd6), [https://lists.gnu.org/archive/html/bug-inetutils/2023-07/msg00000.html](https://lists.gnu.org/archive/html/bug-inetutils/2023-07/msg00000.html).