Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilité · NVD

CVE-2022-42919

CVE-2022-42919, classée high par l'éditeur : 3 apps suivies concernées, toutes corrigées ou à statut indéterminable en version courante.

Gravité (CVSS)
7.8

CVSS base ; la gravité est une note éditeur (échelle différente)

Exploitation
0.7 %

EPSS, prédiction à 30 jours

Apps suivies
3
Encore exposées
0
Échelle bulletin éditeur : CVSS NVD en attente

EN Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized from any user in the same machine local network namespace, which in many system configurations means any user on the same machine. Pickles can execute arbitrary code. Thus, this allows for local user privilege escalation to the user that any forkserver process is running as. Setting multiprocessing.util.abstract_sockets_supported to False is a workaround. The forkserver start method for multiprocessing is not the default start method. This issue is Linux specific because only Linux supports abstract namespace sockets. CPython before 3.9 does not make use of Linux abstract namespace sockets by default. Support for users manually specifying an abstract namespace socket was added as a bugfix in 3.7.8 and 3.8.3, but users would need to make specific uncommon API calls in order to do that in CPython before 3.9.

Vecteur d'attaque : Local Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS 0.75% au-dessus de la médiane percentile 52.9%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

  • Python 3.12 Windows winget:Python.Python.3.12
    Affecté ≥3.7.3 ≤3.7.15 Corrigé > 3.7.15 Dernière suivie 3.12.10 patchée
  • Python 3.13 Windows winget:Python.Python.3.13
    Affecté ≥3.7.3 ≤3.7.15 Corrigé > 3.7.15 Dernière suivie 3.13.15 patchée
  • Python 3.14 Windows winget:Python.Python.3.14
    Affecté ≥3.7.3 ≤3.7.15 Corrigé > 3.7.15 Dernière suivie 3.14.7 patchée
Configurations CPE vulnérables (4)
Vendor Produit Versions
python python
Toutes plateformes (wildcard)
≥3.7.3 ≤3.7.15
python python
Toutes plateformes (wildcard)
≥3.8.3 ≤3.8.15
python python
Toutes plateformes (wildcard)
≥3.9.0 <3.9.16
python python
Toutes plateformes (wildcard)
≥3.10.0 <3.10.9
Voir sur NVD ↗