CVE-2018-15687
published 2018-10-26CVE-2018-15687: A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd…
high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EXPLOIT
A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | systemd | < systemd 239-11 (bookworm) | systemd 239-11 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_systemd_239-31_on_cbl_mariner_1.0 | — | — |
| systemd | systemd | unspecified – 239 | — |
| systemd_project | systemd | >= 0 < 239-11 | 239-11 |
| systemd_project | systemd | >= 0 < 239-11 | 239-11 |
| systemd_project | systemd | >= 0 < 239-11 | 239-11 |
| systemd_project | systemd | >= 0 < 239-11 | 239-11 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.9 | 229-4ubuntu21.9 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.10 | 229-4ubuntu21.10 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.8 | 229-4ubuntu21.8 |
| systemd_project | systemd | >= 0 < 237-3ubuntu10.9 | 237-3ubuntu10.9 |
| systemd_project | systemd | >= 0 < 237-3ubuntu10.6 | 237-3ubuntu10.6 |
| systemd_project | systemd | >= 235 < 240 | 240 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH