Bugzilla – Bug 1226422
VUL-0: CVE-2024-36587: DNSCrypt-proxy: escalate privileges to root via overwriting the binary dnscrypt-proxy
Last modified: 2024-06-17 08:40:34 UTC
Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to root via overwriting the binary dnscrypt-proxy. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-36587 https://www.cve.org/CVERecord?id=CVE-2024-36587 https://github.com/go-compile/security-advisories/blob/master/vulns/CVE-2024-36587.md https://bugzilla.redhat.com/show_bug.cgi?id=2292346
Not affected when installed via zypper, executable is in /usr/sbin/dnscrypt-proxy with the right permission.