CVE-2019-18192

Severity
7.8HIGH
EPSS
0.1%
top 71.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 17
Latest updateMay 24

Description

GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

NVDgnu/guix1.0.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fgxh-j7f7-7jvg: GNU Guix 12022-05-24
CVEList
CVE-2019-18192: GNU Guix 12019-10-17

📋Vendor Advisories

1
Debian
CVE-2019-18192: guix - GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account ...2019