PT-2018-3575 · Keepalived+4 · Keepalived+4

Jsegitz

·

Published

2018-10-25

·

Updated

2024-06-15

·

CVE-2018-19044

CVSS v2.0

5.5

Medium

VectorAV:L/AC:H/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions keepalived versions 2.0.8
Description The issue is related to the implementation of PrintData or PrintStats calls in the Keepalived network traffic balancing system, which is associated with incorrect link resolution before accessing a file. This could allow an attacker to overwrite arbitrary files. Local users can exploit this to overwrite files if fs.protected symlinks is set to 0, for example, by creating a symlink from /tmp/keepalived.data or /tmp/keepalived.stats to /etc/passwd.
Recommendations For keepalived version 2.0.8, consider setting fs.protected symlinks to 1 to prevent exploitation, and avoid using symlinks in temporary file paths for PrintData or PrintStats calls until a patch is available.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2627
BDU:2020-05693
CESA-2019_2285
CVE-2018-19044
MGASA-2018-0494
OPENSUSE-SU-2018_4212-1
OPENSUSE-SU-2024:10893-1
RHSA-2019:2285
RHSA-2019_2285
SUSE-SU-2020:0779-1
SUSE-SU-2020_0779-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Keepalived