PT-2018-5222 · Gnu · Guixsd

Ludovic Courtã¨S

·

Publicado

2018-01-02

·

Atualizado

2018-01-30

·

CVE-2017-1000455

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GuixSD versions prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d
Description The issue arises from the incorrect use of POSIX hard links, resulting in the creation of setuid executables in "the store". This violates a fundamental security assumption of GNU Guix, potentially leading to security breaches.
Recommendations For GuixSD versions prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d, update to a version that includes the fix for the incorrect use of POSIX hard links to prevent the creation of setuid executables in "the store".

Correção

Origin Validation Error

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-1000455

Produtos afetados

Guixsd