PT-2018-17632 · Canonical · Base-Files+1

Sander Bos

·

Published

2018-08-21

·

Updated

2023-01-19

·

CVE-2018-6557

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions base-files package in Ubuntu versions 18.04 before 10.1ubuntu2.2 base-files package in Ubuntu versions 18.10 before 10.1ubuntu6
Description The MOTD update script in the base-files package incorrectly handled temporary files. A local attacker could use this issue to cause a denial of service, or possibly escalate privileges if kernel symlink restrictions were disabled.
Recommendations For Ubuntu 18.04 before 10.1ubuntu2.2, update to version 10.1ubuntu2.2 or later to resolve the issue. For Ubuntu 18.10 before 10.1ubuntu6, update to version 10.1ubuntu6 or later to resolve the issue.

Fix

DoS

Link Following

Weakness Enumeration

Related Identifiers

CVE-2018-6557
USN-3748-1

Affected Products

Ubuntu
Base-Files