Back to Database
Status published
Critical
CVE-2022-25643
seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with...
Vulnerability Description
seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The attack vector is a user-supplied socket pathname.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-25643
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/kennylevinsen/seatd/tags
- https://github.com/kennylevinsen/seatd/compare/0.6.3...0.6.4
- https://lists.sr.ht/~kennylevinsen/seatd-announce/%3CETEO7R.QG8B1KGD531R1%40kl.wtf%3E
- https://github.com/kennylevinsen/seatd/commit/10658dc5439db429af0088295a051c53925a4416
- https://github.com/kennylevinsen/seatd/commit/7cffe0797fdb17a9c08922339465b1b187394335
- https://nvd.nist.gov/vuln/detail/CVE-2022-25643
Affected Vendor
seatd project
View all reports →Affected Software
seatd
Vulnerable Versions:
0.6.0
Timeline
Official Publish:
February 22nd, 2022
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.