Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-18078

Опубликовано: 29 янв. 2018
Источник: ubuntu
Приоритет: low
CVSS2: 4.6
CVSS3: 7.8

Описание

systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.

РелизСтатусПримечание
artful

ignored

devel

ignored

esm-infra-legacy/trusty

ignored

esm-infra/xenial

ignored

precise/esm

DNE

trusty

ignored

trusty/esm

ignored

upstream

needs-triage

xenial

ignored

Показывать по

Ссылки на источники

4.6 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 6.7
redhat
около 8 лет назад

systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.

CVSS3: 7.8
nvd
около 8 лет назад

systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.

CVSS3: 7.8
debian
около 8 лет назад

systemd-tmpfiles in systemd before 237 attempts to support ownership/p ...

suse-cvrf
почти 8 лет назад

Security update for systemd

suse-cvrf
почти 8 лет назад

Security update for systemd

4.6 Medium

CVSS2

7.8 High

CVSS3