CVE-2017-18018

CWE-362Race Condition7 documents6 sources
Severity
7.1HIGH
EPSS
0.1%
top 82.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 4
Latest updateJan 8

Description

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2

Affected Packages1 packages

NVDgnu/coreutils8.29

🔴Vulnerability Details

2
CVEList
CVE-2017-18018: In GNU Coreutils through 82018-01-04
OSV
CVE-2017-18018: In GNU Coreutils through 82018-01-04

📋Vendor Advisories

2
Red Hat
coreutils: race condition vulnerability in chown and chgrp2017-12-20
Debian
CVE-2017-18018: coreutils - In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent ...2017

💬Community

2
Bugzilla
CVE-2017-18018 coreutils: race condition vulnerability in chown and chgrp [fedora-all]2018-01-08
Bugzilla
CVE-2017-18018 coreutils: race condition vulnerability in chown and chgrp2018-01-08