PT-2018-17632 · Canonical · Base-Files+1
Sander Bos
·
Published
2018-08-21
·
Updated
2023-01-19
·
CVE-2018-6557
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
base-files package in Ubuntu versions 18.04 before 10.1ubuntu2.2
base-files package in Ubuntu versions 18.10 before 10.1ubuntu6
Description
The MOTD update script in the base-files package incorrectly handled temporary files. A local attacker could use this issue to cause a denial of service, or possibly escalate privileges if kernel symlink restrictions were disabled.
Recommendations
For Ubuntu 18.04 before 10.1ubuntu2.2, update to version 10.1ubuntu2.2 or later to resolve the issue.
For Ubuntu 18.10 before 10.1ubuntu6, update to version 10.1ubuntu6 or later to resolve the issue.
Fix
DoS
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ubuntu
Base-Files