PT-2018-3552 · Systemd+2 · Systemd+2
Michael Orlitzky
·
Published
2018-01-29
·
Updated
2024-06-15
·
CVE-2017-18078
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
systemd versions prior to 237
Description:
The issue is related to incorrect link resolution before file access in the systemd-tmpfiles daemon, allowing an attacker to bypass existing access restrictions and potentially disclose protected information. This can occur when the fs.protected hardlinks setting is disabled by an administrator and an attacker creates hard links to sensitive files. Local users can exploit this to change ownership or permissions of files they normally cannot access, such as the /etc/passwd file.
Recommendations:
For versions prior to 237, update to version 237 or later to resolve the issue.
As a temporary workaround, consider enabling the fs.protected hardlinks sysctl to prevent the creation of hard links to sensitive files.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Suse
Systemd