uptimed before 0.4.6-r1 on Gentoo allows local users (with access to the uptimed user account) to gain root privileges by creating a hard link within the /var/spool/uptimed directory, because there is an unsafe chown -R call.
{ "binaries": [ { "binary_name": "libuptimed0", "binary_version": "1:0.3.17-4" }, { "binary_name": "uprecords-cgi", "binary_version": "1:0.3.17-4" }, { "binary_name": "uptimed", "binary_version": "1:0.3.17-4" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-36657.json"
{ "binaries": [ { "binary_name": "uptimed", "binary_version": "1:0.4.0+git20150923.6b22106-2" } ] }
{ "binaries": [ { "binary_name": "uptimed", "binary_version": "1:0.4.2-1" } ] }
{ "binaries": [ { "binary_name": "uptimed", "binary_version": "1:0.4.6-3" } ] }
{ "binaries": [ { "binary_name": "uptimed", "binary_version": "1:0.4.6-3.1" } ] }
{ "binaries": [ { "binary_name": "uptimed", "binary_version": "1:0.4.6-3.1build1" } ] }