CVE-2018-6954
published 2018-02-13CVE-2018-6954: systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.53%
41.4th percentile
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | systemd | < systemd 238-1 (bookworm) | systemd 238-1 (bookworm) |
| opensuse | leap | — | — |
| systemd_project | systemd | <= 237 | — |
| systemd_project | systemd | >= 0 < 238-1 | 238-1 |
| systemd_project | systemd | >= 0 < 238-1 | 238-1 |
| systemd_project | systemd | >= 0 < 238-1 | 238-1 |
| systemd_project | systemd | >= 0 < 238-1 | 238-1 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.9 | 229-4ubuntu21.9 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.10 | 229-4ubuntu21.10 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.8 | 229-4ubuntu21.8 |
| systemd_project | systemd | >= 0 < 237-3ubuntu10.9 | 237-3ubuntu10.9 |
| systemd_project | systemd | >= 0 < 237-3ubuntu10.6 | 237-3ubuntu10.6 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
systemd regression
vendor_ubuntu·2018-11-27·CVSS 7.8
CVE-2018-6954 [HIGH] systemd regression
Title: systemd regression
Summary: USN-3816-1 caused a regression in systemd-tmpfiles.
USN-3816-1 fixed vulnerabilities in systemd. The fix for CVE-2018-6954
caused a regression in systemd-tmpfiles when running Ubuntu inside a
container on some older kernels. This issue only affected Ubuntu 16.04
LTS. In order to continue to support this configuration, the fixes for
CVE-2018-6954 have been reverted.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that unit_deserialize incorrectly handled status messages
above a certain length. A local attacker could potentially exploit this via
NotifyAccess to inject arbitrary state across re-execution and obtain root
privileges. (CVE-2018-15686)
Jann Horn discovered a race condition in chown_one(). A local attacke
Ubuntu
systemd vulnerability
vendor_ubuntu·2018-11-19·CVSS 7.8
CVE-2018-6954 [HIGH] systemd vulnerability
Title: systemd vulnerability
Summary: systemd-tmpfiles could be made to change ownership of arbitrary files.
USN-3816-1 fixed several vulnerabilities in systemd. However, the fix for
CVE-2018-6954 was not sufficient. This update provides the remaining fixes.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that unit_deserialize incorrectly handled status messages
above a certain length. A local attacker could potentially exploit this via
NotifyAccess to inject arbitrary state across re-execution and obtain root
privileges. (CVE-2018-15686)
Jann Horn discovered a race condition in chown_one(). A local attacker
could potentially exploit this by setting arbitrary permissions on certain
files to obtain root privileges. This issue only affected Ubuntu 18
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2018-11-12·CVSS 7.8
CVE-2018-15686 [HIGH] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
Jann Horn discovered that unit_deserialize incorrectly handled status messages
above a certain length. A local attacker could potentially exploit this via
NotifyAccess to inject arbitrary state across re-execution and obtain root
privileges. (CVE-2018-15686)
Jann Horn discovered a race condition in chown_one(). A local attacker
could potentially exploit this by setting arbitrary permissions on certain
files to obtain root privileges. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 18.10. (CVE-2018-15687)
It was discovered that systemd-tmpfiles mishandled symlinks in
non-terminal path components. A local attacker could potentially exploit
this by gaining ownership of certain files to obtain root
Red Hat
systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files
vendor_redhat·2018-01-25·CVSS 7.8
CVE-2018-6954 [HIGH] CWE-59 systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files
systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
It has been discovered that systemd-tmpfiles mishandles symbolic links present in non-terminal path components. In some configurations a local user could use this vulnerability to get access to arbitrary files when the systemd-tmpfiles command is run.
Statement: This flaw affects in particular those systems where custom tmpfil
Debian
CVE-2018-6954: systemd - systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-termi...
vendor_debian·2018·CVSS 7.8
CVE-2018-6954 [HIGH] CVE-2018-6954: systemd - systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-termi...
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
Scope: local
bookworm: resolved (fixed in 238-1)
bullseye: resolved (fixed in 238-1)
forky: resolved (fixed in 238-1)
sid: resolved (fixed in 238-1)
trixie: resolved (fixed in 238-1)
GHSA
GHSA-fgm4-rh7c-g9fg: systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of a
ghsa_unreviewed·2022-05-13
CVE-2018-6954 [HIGH] CWE-59 GHSA-fgm4-rh7c-g9fg: systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of a
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
OSV
systemd regression
osv·2018-11-27·CVSS 7.8
CVE-2018-6954 [HIGH] systemd regression
systemd regression
USN-3816-1 fixed vulnerabilities in systemd. The fix for CVE-2018-6954
caused a regression in systemd-tmpfiles when running Ubuntu inside a
container on some older kernels. This issue only affected Ubuntu 16.04
LTS. In order to continue to support this configuration, the fixes for
CVE-2018-6954 have been reverted.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that unit_deserialize incorrectly handled status messages
above a certain length. A local attacker could potentially exploit this via
NotifyAccess to inject arbitrary state across re-execution and obtain root
privileges. (CVE-2018-15686)
Jann Horn discovered a race condition in chown_one(). A local attacker
could potentially exploit this by setting arbitrary permissions on
OSV
systemd vulnerability
osv·2018-11-19·CVSS 7.8
CVE-2018-6954 [HIGH] systemd vulnerability
systemd vulnerability
USN-3816-1 fixed several vulnerabilities in systemd. However, the fix for
CVE-2018-6954 was not sufficient. This update provides the remaining fixes.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that unit_deserialize incorrectly handled status messages
above a certain length. A local attacker could potentially exploit this via
NotifyAccess to inject arbitrary state across re-execution and obtain root
privileges. (CVE-2018-15686)
Jann Horn discovered a race condition in chown_one(). A local attacker
could potentially exploit this by setting arbitrary permissions on certain
files to obtain root privileges. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 18.10. (CVE-2018-15687)
It was discovered that systemd-tmpfiles mish
OSV
systemd vulnerabilities
osv·2018-11-12·CVSS 7.8
CVE-2018-15686 [HIGH] systemd vulnerabilities
systemd vulnerabilities
Jann Horn discovered that unit_deserialize incorrectly handled status messages
above a certain length. A local attacker could potentially exploit this via
NotifyAccess to inject arbitrary state across re-execution and obtain root
privileges. (CVE-2018-15686)
Jann Horn discovered a race condition in chown_one(). A local attacker
could potentially exploit this by setting arbitrary permissions on certain
files to obtain root privileges. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 18.10. (CVE-2018-15687)
It was discovered that systemd-tmpfiles mishandled symlinks in
non-terminal path components. A local attacker could potentially exploit
this by gaining ownership of certain files to obtain root privileges. This
issue only affected Ubuntu 16.04 LTS and Ubuntu
OSV
CVE-2018-6954: systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of a
osv·2018-02-13·CVSS 7.8
CVE-2018-6954 [HIGH] CVE-2018-6954: systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of a
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-8006 activemq: Cross-site scripting (XSS) via QueueFilter parameter
bugzilla·2018-08-28·CVSS 6.1
CVE-2018-8006 [MEDIUM] CVE-2018-8006 activemq: Cross-site scripting (XSS) via QueueFilter parameter
CVE-2018-8006 activemq: Cross-site scripting (XSS) via QueueFilter parameter
Apache ActiveMQ before version 5.15.5 is vulnerable to cross-site scripting (XSS) flaw via the QueueFilter parameter. An attacker could exploit this by feeding a URL encoded script to the QueueFilter parameter in the URI.
External Reference:
https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2018-008/?fid=11632
Upstream Bug:
https://issues.apache.org/jira/browse/AMQ-6954
Upstream Patches:
https://git-wip-us.apache.org/repos/asf?p=activemq.git;h=d25de5d
https://git-wip-us.apache.org/repos/asf?p=activemq.git;h=d8c80a9
Discussion:
Created activemq tracking bugs for this issue:
Affects: fedora-all [bug 1622775]
---
This vulnerability is out of security support scope for the following
Bugzilla
CVE-2018-6954 systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files
bugzilla·2018-02-14·CVSS 7.8
CVE-2018-6954 [HIGH] CVE-2018-6954 systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files
CVE-2018-6954 systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files
systemd-tmpfiles in systemd through version 237 mishandles symlinks present in non-terminal path components, allowing local users to obtain ownership of arbitrary files under certain configurations.
Depending on the configuration and access to files in /etc/tmpfiles.d, a local user can potentially create a symlink allowing them obtain full access to arbitrary files when the systemd-tmpfiles command is run.
This occurs even if the fs.protected_symlinks sysctl is turned on.
Upstream Issue:
https://github.com/systemd/systemd/issues/7986
Discussion:
Created systemd tracking bugs for this issue:
Affects: fedora-all [bug 1545018]
---
Patches:
https://github.com/syst
Bugzilla
CVE-2018-6954 systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files [fedora-all]
bugzilla·2018-02-14·CVSS 7.8
CVE-2018-6954 [HIGH] CVE-2018-6954 systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files [fedora-all]
CVE-2018-6954 systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messag
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.htmlhttps://github.com/systemd/systemd/issues/7986https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://usn.ubuntu.com/3816-1/https://usn.ubuntu.com/3816-2/http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.htmlhttps://github.com/systemd/systemd/issues/7986https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://usn.ubuntu.com/3816-1/https://usn.ubuntu.com/3816-2/
2018-02-13
Published