Do your applications use this vulnerable package?
Test your applications
Overview
The MOTD update script in the base-files package in Ubuntu 18.04 LTS before 10.1ubuntu2.2, and Ubuntu 18.10 before 10.1ubuntu6 incorrectly handled temporary files. A local attacker could use this issue to cause a denial of service, or possibly escalate privileges if kernel symlink restrictions were disabled.
References
CVSS Score
7.0
low severity
-
Attack VectorLocal
-
Attack ComplexityHigh
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2018-6557
- CWE
- CWE-59
- Snyk ID
- SNYK-UBUNTU1804-BASEFILES-261368
- Disclosed
- 21 Aug, 2018
- Published
- 22 Aug, 2018