PT-2018-17632 · Canonical · Base-Files+1
Sander Bos
·
Publicado
2018-08-21
·
Atualizado
2023-01-19
·
CVE-2018-6557
CVSS v3.1
7.0
Alta
| Vetor | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
base-files package in Ubuntu versions 18.04 before 10.1ubuntu2.2
base-files package in Ubuntu versions 18.10 before 10.1ubuntu6
Description
The MOTD update script in the base-files package incorrectly handled temporary files. A local attacker could use this issue to cause a denial of service, or possibly escalate privileges if kernel symlink restrictions were disabled.
Recommendations
For Ubuntu 18.04 before 10.1ubuntu2.2, update to version 10.1ubuntu2.2 or later to resolve the issue.
For Ubuntu 18.10 before 10.1ubuntu6, update to version 10.1ubuntu6 or later to resolve the issue.
Correção
DoS
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ubuntu
Base-Files