PT-2018-5222 · Gnu · Guixsd
Ludovic Courtã¨S
·
Publicado
2018-01-02
·
Atualizado
2018-01-30
·
CVE-2017-1000455
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GuixSD versions prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d
Description
The issue arises from the incorrect use of POSIX hard links, resulting in the creation of setuid executables in "the store". This violates a fundamental security assumption of GNU Guix, potentially leading to security breaches.
Recommendations
For GuixSD versions prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d, update to a version that includes the fix for the incorrect use of POSIX hard links to prevent the creation of setuid executables in "the store".
Correção
Origin Validation Error
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Guixsd