cbcvebase.
CVE-2018-15687
published 2018-10-26

CVE-2018-15687: A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd…

high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EXPLOIT
A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.

Affected

18 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiansystemd< systemd 239-11 (bookworm)systemd 239-11 (bookworm)
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_systemd_239-31_on_cbl_mariner_1.0
systemdsystemdunspecified – 239
systemd_projectsystemd>= 0 < 239-11239-11
systemd_projectsystemd>= 0 < 239-11239-11
systemd_projectsystemd>= 0 < 239-11239-11
systemd_projectsystemd>= 0 < 239-11239-11
systemd_projectsystemd>= 0 < 229-4ubuntu21.9229-4ubuntu21.9
systemd_projectsystemd>= 0 < 229-4ubuntu21.10229-4ubuntu21.10
systemd_projectsystemd>= 0 < 229-4ubuntu21.8229-4ubuntu21.8
systemd_projectsystemd>= 0 < 237-3ubuntu10.9237-3ubuntu10.9
systemd_projectsystemd>= 0 < 237-3ubuntu10.6237-3ubuntu10.6
systemd_projectsystemd>= 235 < 240240

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH