Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-18018

Опубликовано: 20 дек. 2017
Источник: redhat
CVSS3: 4.2

Описание

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

Отчет

For this vulnerability the fix was an update to the documentation. For more details please visit: https://www.openwall.com/lists/oss-security/2018/01/04/3 http://michael.orlitzky.com/cves/cve-2017-18018.xhtml Red Hat Enterprise Linux 8 ships already updated version of the coreutils package (version 8.30).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4coreutilsWill not fix
Red Hat Enterprise Linux 5coreutilsWill not fix
Red Hat Enterprise Linux 6coreutilsWill not fix
Red Hat Enterprise Linux 7coreutilsWill not fix
Red Hat Enterprise Linux 8coreutilsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=1532284coreutils: race condition vulnerability in chown and chgrp

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 8 лет назад

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

CVSS3: 7.1
nvd
около 8 лет назад

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

CVSS3: 7.1
debian
около 8 лет назад

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does no ...

4.2 Medium

CVSS3