uptimed before 0.4.6-r1 on Gentoo allows local users (with access to the uptimed user account) to gain root privileges by creating a hard link within the /var/spool/uptimed directory, because there is an unsafe chown -R call.
{ "binaries": [ { "binary_version": "1:0.3.17-4", "binary_name": "libuptimed0" }, { "binary_version": "1:0.3.17-4", "binary_name": "uprecords-cgi" }, { "binary_version": "1:0.3.17-4", "binary_name": "uptimed" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-36657.json"
{ "binaries": [ { "binary_version": "1:0.4.0+git20150923.6b22106-2", "binary_name": "uptimed" } ] }
{ "binaries": [ { "binary_version": "1:0.4.2-1", "binary_name": "uptimed" } ] }
{ "binaries": [ { "binary_version": "1:0.4.6-3", "binary_name": "uptimed" } ] }
{ "binaries": [ { "binary_version": "1:0.4.6-3.1", "binary_name": "uptimed" } ] }
{ "binaries": [ { "binary_version": "1:0.4.6-3.1build1", "binary_name": "uptimed" } ] }