Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20197

Опубликовано: 07 янв. 2021
Источник: redhat
CVSS3: 4.2

Описание

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

There is an open race window when writing output in the following utilities in GNU binutils1: ar, objcopy, strip, and ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6binutilsOut of support scope
Red Hat Enterprise Linux 7binutilsOut of support scope
Red Hat Enterprise Linux 8gcc-toolset-10-binutilsFix deferred
Red Hat Enterprise Linux 8gcc-toolset-9-binutilsAffected
Red Hat Enterprise Linux 9binutilsAffected
Red Hat Enterprise Linux 8binutilsFixedRHSA-2021:436409.11.2021
Red Hat Enterprise Linux 8binutilsFixedRHSA-2021:436409.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=1913743binutils: Race window allows users to own arbitrary files

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
около 5 лет назад

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

CVSS3: 6.3
nvd
около 5 лет назад

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

CVSS3: 6.3
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 6.3
debian
около 5 лет назад

There is an open race window when writing output in the following util ...

CVSS3: 6.3
github
почти 4 года назад

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

4.2 Medium

CVSS3