CVE-2017-18018
ADVISORY - debianSummary
In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.
- coreutils (unimportant) http://lists.gnu.org/archive/html/coreutils/2017-12/msg00045.html https://www.openwall.com/lists/oss-security/2018/01/04/3 Documentation patches proposed: https://lists.gnu.org/archive/html/coreutils/2017-12/msg00072.html https://lists.gnu.org/archive/html/coreutils/2017-12/msg00073.html Neutralised by kernel hardening
EPSS Score: 0.00056 (0.175)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
ADVISORY - redhat
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Debian
CREATED
UPDATED
ADVISORY IDCVE-2017-18018
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AlowPackage | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
---|---|---|---|---|---|
debian/coreutils | deb | debian | 12 | >=9.1-1 | Not yet available |
debian/coreutils | deb | debian | 13 | >=9.7-3 | Not yet available |
debian/coreutils | deb | debian | 11 | >=8.32-4 | Not yet available |
debian/coreutils | deb | debian | unstable | >=9.7-3 | Not yet available |
Severity and metrics
No CVSS data available from this advisory.
NIST
CREATED
UPDATED
ADVISORY IDCVE-2017-18018
EXPLOITABILITY SCORE
1.8
EXPLOITS FOUND
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.1highAlpine
CREATED
UPDATED
ADVISORY IDCVE-2017-18018
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2017-18018
EXPLOITABILITY SCORE
1.0
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
4.7lowRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2017-18018
EXPLOITABILITY SCORE
0.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
4.2mediumintheWild
CREATED
UPDATED
ADVISORY IDCVE-2017-18018
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-