Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-18018

Опубликовано: 04 янв. 2018
Источник: nvd
CVSS3: 4.7
CVSS3: 7.1
CVSS2: 1.9
EPSS Низкий

Описание

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*
Версия до 8.29 (включая)

EPSS

Процентиль: 18%
0.00056
Низкий

4.7 Medium

CVSS3

7.1 High

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-362
CWE-362

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 8 лет назад

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

CVSS3: 4.2
redhat
около 8 лет назад

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

CVSS3: 7.1
debian
около 8 лет назад

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does no ...

EPSS

Процентиль: 18%
0.00056
Низкий

4.7 Medium

CVSS3

7.1 High

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-362
CWE-362