PT-2013-3597 · Gnu+3 · Glibc+3

Martin Carpenter

·

Publicado

2013-10-09

·

Atualizado

2024-06-15

·

CVE-2013-2207

CVSS v2.0

2.6

Baixa

VetorAV:L/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions glibc versions prior to 2.18
Description The issue concerns a problem with pt chown in the GNU C Library, where it does not properly check permissions for tty files. This allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.
Recommendations For versions prior to 2.18, update to version 2.18 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2084
CVE-2013-2207
MGASA-2013-0340
OPENSUSE-SU-2024:10154-1
SUSE-SU-2015:1424-1
SUSE-SU-2015_1424-1
SUSE-SU-2016:0470-1
USN-2985-1
USN-2985-2

Produtos afetados

Alt Linux
Suse
Ubuntu
Glibc