CVE-2019-18192
published 2019-10-17CVE-2019-18192: GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.5th percentile
GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | guix | — | — |
| gnu | guix | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fgxh-j7f7-7jvg: GNU Guix 1
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2019-18192 [HIGH] CWE-732 GHSA-fgxh-j7f7-7jvg: GNU Guix 1
GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365.
Debian
CVE-2019-18192: guix - GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account ...
vendor_debian·2019·CVSS 7.8
CVE-2019-18192 [HIGH] CVE-2019-18192: guix - GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account ...
GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365.
Scope: local
bullseye: resolved
sid: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-10-17
Published