PT-2013-3597 · Gnu+3 · Glibc+3
Martin Carpenter
·
Publicado
2013-10-09
·
Atualizado
2024-06-15
·
CVE-2013-2207
CVSS v2.0
2.6
Baixa
| Vetor | AV:L/AC:H/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
glibc versions prior to 2.18
Description
The issue concerns a problem with
pt chown in the GNU C Library, where it does not properly check permissions for tty files. This allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.Recommendations
For versions prior to 2.18, update to version 2.18 or later to resolve the issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Ubuntu
Glibc