An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.
{
"binaries": [
{
"binary_name": "bsdutils",
"binary_version": "1:2.20.1-5.1ubuntu20.9"
},
{
"binary_name": "libblkid-dev",
"binary_version": "2.20.1-5.1ubuntu20.9"
},
{
"binary_name": "libblkid1",
"binary_version": "2.20.1-5.1ubuntu20.9"
},
{
"binary_name": "libmount-dev",
"binary_version": "2.20.1-5.1ubuntu20.9"
},
{
"binary_name": "libmount1",
"binary_version": "2.20.1-5.1ubuntu20.9"
},
{
"binary_name": "libuuid1",
"binary_version": "2.20.1-5.1ubuntu20.9"
},
{
"binary_name": "mount",
"binary_version": "2.20.1-5.1ubuntu20.9"
},
{
"binary_name": "util-linux",
"binary_version": "2.20.1-5.1ubuntu20.9"
},
{
"binary_name": "util-linux-locales",
"binary_version": "2.20.1-5.1ubuntu20.9"
},
{
"binary_name": "uuid-dev",
"binary_version": "2.20.1-5.1ubuntu20.9"
},
{
"binary_name": "uuid-runtime",
"binary_version": "2.20.1-5.1ubuntu20.9"
}
],
"priority_reason": "Non-default and improbable configuration"
}