PT-2018-14564 · Crossroads · Crossroads
Helmut Grohne
+1
·
Published
2018-10-26
·
Updated
2019-10-03
·
CVE-2018-18654
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Crossroads version 2.81
Description
The issue arises from improper handling of the /tmp directory during the build process of xr, allowing a local attacker to create a world-writable subdirectory in a specific location under /tmp. The attacker can then wait for a user process to copy xr into this subdirectory and subsequently replace the contents with a Trojan horse version of xr.
Recommendations
For Crossroads version 2.81, consider restricting access to the /tmp directory to prevent unauthorized modifications, and ensure that user processes copying xr into /tmp use secure and isolated temporary directories to minimize the risk of exploitation.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crossroads