Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Readline crime: exploiting a SUID logic bug

Summary

A logic bug in readline leaks partial file contents when parsing the INPUTRC environment variable, exploitable via SUID binaries like chfn for lateral movement; reported and patched in February 2022.
Published
Collected

original ↗

Related coverage

back