CVE-2018-6954Link Following in Project Systemd

CWE-59Link Following14 documents8 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 68.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13
Latest updateMay 13

Description

systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

Debiansystemd_project/systemd< 238-1+3
Ubuntusystemd_project/systemd< 229-4ubuntu21.9+2
NVDopensuse/leap42.3

Also affects: Ubuntu Linux 16.04, 18.04, 18.10

Patches

🔴Vulnerability Details

5
GHSA
GHSA-fgm4-rh7c-g9fg: systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of a2022-05-13
OSV
systemd regression2018-11-27
OSV
systemd vulnerability2018-11-19
CVEList
CVE-2018-6954: systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of a2018-02-13
OSV
CVE-2018-6954: systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of a2018-02-13

📋Vendor Advisories

5
Ubuntu
systemd regression2018-11-27
Ubuntu
systemd vulnerability2018-11-19
Ubuntu
systemd vulnerabilities2018-11-12
Red Hat
systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files2018-01-25
Debian
CVE-2018-6954: systemd - systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-termi...2018

💬Community

3
Bugzilla
CVE-2018-8006 activemq: Cross-site scripting (XSS) via QueueFilter parameter2018-08-28
Bugzilla
CVE-2018-6954 systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files2018-02-14
Bugzilla
CVE-2018-6954 systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files [fedora-all]2018-02-14
CVE-2018-6954 — Link Following in Project Systemd | cvebase