Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-2616

Опубликовано: 27 июл. 2018
Источник: debian
EPSS Низкий

Описание

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
shadowfixed1:4.4-4package
util-linuxfixed2.29.2-1package
coreutilsfixed8.20-1package

Примечания

  • https://github.com/shadow-maint/shadow/commit/08fd4b69e84364677a10e519ccb25b71710ee686

  • https://github.com/karelzak/util-linux/commit/dffab154d29a288aa171ff50263ecc8f2e14a891

  • Coreutils: Removed from source in https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=928dd737

  • and not installed by default since 2007.

EPSS

Процентиль: 19%
0.00062
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.

CVSS3: 5.5
redhat
больше 8 лет назад

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.

CVSS3: 5.5
nvd
больше 7 лет назад

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.

suse-cvrf
больше 8 лет назад

Security update for util-linux

suse-cvrf
больше 8 лет назад

Security update for util-linux

EPSS

Процентиль: 19%
0.00062
Низкий