Access Restriction Bypass
Affecting systemd package, versions <229-4ubuntu21.15
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
References
CVSS Score
7.8
medium severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2018-6954
- Snyk ID
- SNYK-UBUNTU1604-SYSTEMD-305047
- Disclosed
- 13 Feb, 2018
- Published
- 13 Feb, 2018