Do your applications use this vulnerable package?
Test your applications
Overview
A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
References
CVSS Score
4.7
medium severity
-
Attack VectorLocal
-
Attack ComplexityHigh
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2017-2616
- CWE
- CWE-267 CWE-362
- Snyk ID
- SNYK-DEBIAN8-UTILLINUX-285840
- Disclosed
- 27 Jul, 2018
- Published
- 27 Jun, 2018