enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/.. substring.
{ "binaries": [ { "binary_name": "e17", "binary_version": "0.17.6-1" }, { "binary_name": "e17-data", "binary_version": "0.17.6-1" }, { "binary_name": "e17-dev", "binary_version": "0.17.6-1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37706.json"
{ "binaries": [ { "binary_name": "e17", "binary_version": "0.17.6-1.1" }, { "binary_name": "e17-data", "binary_version": "0.17.6-1.1" }, { "binary_name": "e17-dev", "binary_version": "0.17.6-1.1" } ] }
{ "binaries": [ { "binary_name": "enlightenment", "binary_version": "0.23.1-4" }, { "binary_name": "enlightenment-data", "binary_version": "0.23.1-4" }, { "binary_name": "enlightenment-dev", "binary_version": "0.23.1-4" } ] }
{ "binaries": [ { "binary_name": "enlightenment", "binary_version": "0.25.3-1" }, { "binary_name": "enlightenment-data", "binary_version": "0.25.3-1" }, { "binary_name": "enlightenment-dev", "binary_version": "0.25.3-1" } ] }
{ "binaries": [ { "binary_name": "enlightenment", "binary_version": "0.26.0-2build2" }, { "binary_name": "enlightenment-data", "binary_version": "0.26.0-2build2" }, { "binary_name": "enlightenment-dev", "binary_version": "0.26.0-2build2" } ] }
{ "binaries": [ { "binary_name": "enlightenment", "binary_version": "0.27.1-1" }, { "binary_name": "enlightenment-data", "binary_version": "0.27.1-1" }, { "binary_name": "enlightenment-dev", "binary_version": "0.27.1-1" } ] }