ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36770”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36770
Published
2024-01-15
CVSS:
7.8
ShadowTrackr CVSS:
7.2
Summary:
pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem. This could be exploited by the slurm user to become the owner of root-owned files.