Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-6954

Опубликовано: 13 фев. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.2
CVSS3: 7.8

Описание

systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.

РелизСтатусПримечание
artful

ignored

end of life
bionic

released

237-3ubuntu10.9
cosmic

released

239-7ubuntu10.4
devel

released

239-7ubuntu10.4
esm-infra-legacy/trusty

not-affected

binary not built
esm-infra/bionic

released

237-3ubuntu10.9
esm-infra/xenial

released

229-4ubuntu21.15
precise/esm

DNE

trusty

not-affected

binary not built
trusty/esm

not-affected

binary not built

Показывать по

EPSS

Процентиль: 29%
0.00104
Низкий

7.2 High

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7
redhat
около 8 лет назад

systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.

CVSS3: 7.8
nvd
почти 8 лет назад

systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.

CVSS3: 7.8
debian
почти 8 лет назад

systemd-tmpfiles in systemd through 237 mishandles symlinks present in ...

CVSS3: 7.8
github
больше 3 лет назад

systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.

CVSS3: 7.8
fstec
около 8 лет назад

Уязвимость компонента systemd-tmpfiles демона Systemd, позволяющая нарушителю получить доступ к произвольным файлам

EPSS

Процентиль: 29%
0.00104
Низкий

7.2 High

CVSS2

7.8 High

CVSS3