CVE-2019-15900

9.8
CRITICALCVSS v3.1 Base Score
2.11%
LOW RiskEPSS (81st percentile)

An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. Instead, the uninitialized variable errstr was checked and in some cases returned success even if sscanf failed. The result was that, instead of reporting that the supplied username or group name did not exist, it would execute the command as root.

Published: 10/18/2019
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

10

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

2.11%LOW Exploitation Risk
81st percentile

This vulnerability has a 2.11% probability of being exploited in the next 30 days, ranking higher than 81% of all scored CVEs.

CWE Classification

Advertisement