CVE-2018-7169
published 2018-02-15CVE-2018-7169: An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where…
PriorityP430medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
1.60%
73.1th percentile
An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used "group blacklisting" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | shadow | < shadow 1:4.7-1 (bookworm) | shadow 1:4.7-1 (bookworm) |
| shadow_project | shadow | — | — |
| shadow_project | shadow | >= 0 < 1:4.7-1 | 1:4.7-1 |
| shadow_project | shadow | >= 0 < 1:4.7-1 | 1:4.7-1 |
| shadow_project | shadow | >= 0 < 1:4.7-1 | 1:4.7-1 |
| shadow_project | shadow | >= 0 < 1:4.7-1 | 1:4.7-1 |
| shadow_project | shadow | >= 0 < 1:4.5-1ubuntu2.2 | 1:4.5-1ubuntu2.2 |
| shadow_project | shadow | >= 0 < 1:4.1.5.1-1ubuntu9.5+esm1 | 1:4.1.5.1-1ubuntu9.5+esm1 |
| shadow_project | shadow | >= 0 < 1:4.2-3.1ubuntu5.5+esm1 | 1:4.2-3.1ubuntu5.5+esm1 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m2px-jr9v-8hhp: An issue was discovered in shadow 4
ghsa_unreviewed·2022-05-13
CVE-2018-7169 [MEDIUM] CWE-732 GHSA-m2px-jr9v-8hhp: An issue was discovered in shadow 4
An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used "group blacklisting" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation.
OSV
shadow vulnerabilities
osv·2022-01-27·CVSS 9.8
CVE-2017-12424 [CRITICAL] shadow vulnerabilities
shadow vulnerabilities
It was discovered that shadow incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
expose sensitive information. This issue only affected
Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. (CVE-2017-12424)
It was discovered that shadow incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2018-7169)
OSV
CVE-2018-7169: An issue was discovered in shadow 4
osv·2018-02-15·CVSS 5.3
CVE-2018-7169 [MEDIUM] CVE-2018-7169: An issue was discovered in shadow 4
An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used "group blacklisting" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation.
Ubuntu
shadow vulnerabilities
vendor_ubuntu·2022-01-27·CVSS 9.8
CVE-2018-7169 [CRITICAL] shadow vulnerabilities
Title: shadow vulnerabilities
Summary: Several security issues were fixed in shadow.
It was discovered that shadow incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
expose sensitive information. This issue only affected
Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. (CVE-2017-12424)
It was discovered that shadow incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2018-7169)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-7169: shadow - An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and...
vendor_debian·2018·CVSS 5.3
CVE-2018-7169 [MEDIUM] CVE-2018-7169: shadow - An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and...
An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used "group blacklisting" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation.
Scope: local
bookworm: resolved (fixed in 1:4.7-1)
bullseye: resolved (fixed in 1:4.7-1)
forky: resolved (fixed in 1:4.7-1)
sid: resolved (fixed in 1:4.7-1)
trixie: resolved (fixed in 1:4.7-1)
Red Hat
shadow-utils: newgidmap allows unprivileged user to drop supplementary groups potentially allowing privilege escalation
vendor_redhat·2017-11-14·CVSS 5.3
CVE-2018-7169 [MEDIUM] CWE-271 shadow-utils: newgidmap allows unprivileged user to drop supplementary groups potentially allowing privilege escalation
shadow-utils: newgidmap allows unprivileged user to drop supplementary groups potentially allowing privilege escalation
An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used "group blacklisting" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation.
An issue was discovered in newgidmap, in shadow-utils, that allows an unprivileged user to be placed in a user namespace wh
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-7169 shadow-utils: newgidmap allows unprivileged user to drop supplementary groups potentially allowing privilege escalation [fedora-all]
bugzilla·2018-02-16·CVSS 5.3
CVE-2018-7169 [MEDIUM] CVE-2018-7169 shadow-utils: newgidmap allows unprivileged user to drop supplementary groups potentially allowing privilege escalation [fedora-all]
CVE-2018-7169 shadow-utils: newgidmap allows unprivileged user to drop supplementary groups potentially allowing privilege escalation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg
Bugzilla
CVE-2018-7169 shadow-utils: newgidmap allows unprivileged user to drop supplementary groups potentially allowing privilege escalation
bugzilla·2018-02-16·CVSS 5.3
CVE-2018-7169 [MEDIUM] CVE-2018-7169 shadow-utils: newgidmap allows unprivileged user to drop supplementary groups potentially allowing privilege escalation
CVE-2018-7169 shadow-utils: newgidmap allows unprivileged user to drop supplementary groups potentially allowing privilege escalation
An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used "group blacklisting" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation.
Bug report:
https://bugs.launchpad.net/ubuntu/+source/shadow/+bug/1729357
Upstream patch:
https://github.c
arXiv
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
arxiv_fulltext·2022-09-26
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
Meghna Pancholi
[email protected]
Columbia University
Andreas D. Kellas
[email protected]
Columbia University
Vasileios P. Kemerlis
[email protected]
Brown University
Simha Sethumadhavan
[email protected]
Columbia University
## Abstract
We introduce , a novel technique for automatically learning system
call filtering policies for containerized microservices applications. At
run-time, automatically learns which system calls a program should
be allowed to invoke, while rejecting attempts to call spurious system calls.
Further, addresses many of the shortcomings of state-of-the-art
static analysis-based techniques, such as the ability to generate tight filters
for programs written in interpreted languages such as PHP, Python, and
JavaScript. has a simple and rob
ATT&CK
Exploit Public-Facing Application
mitre_attack·CVSS 9.8
[CRITICAL] Exploit Public-Facing Application
Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets.(Citation: NVD CVE-2016-6662)(Citation: CIS Multiple SMB Vulnerabilities)(Citation: US-CERT TA18-106A Network Infrastructure Devices 2018)(Citation: Cisco Blog Legacy Device Attacks)(Citation: NVD CVE-2014-7169) On ESXi infrastructure, adversaries may exploit exposed OpenSLP s
2018-02-15
Published