Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-2616

Опубликовано: 22 фев. 2017
Источник: redhat
CVSS3: 5.5

Описание

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.

A race condition was found in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5coreutilsWill not fix
Red Hat Enterprise Linux 5shadow-utilsNot affected
Red Hat Enterprise Linux 5util-linuxNot affected
Red Hat Enterprise Linux 6shadow-utilsNot affected
Red Hat Enterprise Linux 6util-linux-ngNot affected
Red Hat Enterprise Linux 7coreutilsNot affected
Red Hat Enterprise Linux 7shadow-utilsNot affected
Red Hat Enterprise Linux 6coreutilsFixedRHSA-2017:065421.03.2017
Red Hat Enterprise Linux 7util-linuxFixedRHSA-2017:090712.04.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-267
https://bugzilla.redhat.com/show_bug.cgi?id=1418710util-linux: Sending SIGKILL to other processes with root privileges via su

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.

CVSS3: 5.5
nvd
больше 7 лет назад

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.

CVSS3: 5.5
debian
больше 7 лет назад

A race condition was found in util-linux before 2.32.1 in the way su h ...

suse-cvrf
больше 8 лет назад

Security update for util-linux

suse-cvrf
больше 8 лет назад

Security update for util-linux

5.5 Medium

CVSS3