PT-2018-3774 · Gnu+4 · Shadow+4

Craig Furman

·

Publicado

2018-02-15

·

Atualizado

2024-06-15

·

CVE-2018-7169

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions shadow version 4.5
Description An issue in the shadow utility allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted, enabling an attacker to remove themselves from a supplementary group. This may allow access to certain filesystem paths if the administrator has used group blacklisting to restrict access. The flaw reverts a security feature in the kernel to prevent privilege escalation.
Recommendations For shadow version 4.5, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2549
ALT-PU-2019-2619
ALT-PU-2023-1679
BDU:2022-00731
CVE-2018-7169
MGASA-2018-0177
OPENSUSE-SU-2024:11378-1
SUSE-SU-2018:0662-1
SUSE-SU-2018_0662-1
USN-5254-1

Produtos afetados

Alt Linux
Astra Linux
Suse
Ubuntu
Shadow