CVE-2021-25630

Source
https://cve.org/CVERecord?id=CVE-2021-25630
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-25630.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-25630
Aliases
  • GHSA-49w3-gr3w-m68v
Published
2021-02-23T16:15:13.253Z
Modified
2026-08-07T11:31:22.930162656Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with privileges, if it's not the case. In the vulnerable version of "loolforkit" this check was wrong, so a normal user could start "loolforkit" and eventually get local root privileges.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "6.4.0"
                },
                {
                    "fixed": "6.4.3"
                }
            ],
            "source": "CPE_RANGE",
            "vendor_product": "collaboraoffice:online",
            "cpes": [
                "cpe:2.3:a:collaboraoffice:online:*:*:*:*:*:*:*:*"
            ]
        }
    ]
}
References

Affected packages

Git / github.com/collaboraonline/online

Affected ranges

Type
GIT
Repo
https://github.com/collaboraonline/online
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "4.2.0"
        },
        {
            "fixed": "4.2.13"
        }
    ],
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:collaboraoffice:online:*:*:*:*:*:*:*:*"
}

Affected versions

Other
co-4-2-0-branch-point
libreoffice-7-0-branch-point
cp-4.*
cp-4.2.11-1
cp-4.2.12-1
cp-4.2.12-2
cp-4.2.4-1
cp-4.2.4-2
cp-4.2.9-1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-25630.json"