PT-2018-5222 · Gnu · Guixsd
Ludovic Courtã¨S
·
Published
2018-01-02
·
Updated
2018-01-30
·
CVE-2017-1000455
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GuixSD versions prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d
Description
The issue arises from the incorrect use of POSIX hard links, resulting in the creation of setuid executables in "the store". This violates a fundamental security assumption of GNU Guix, potentially leading to security breaches.
Recommendations
For GuixSD versions prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d, update to a version that includes the fix for the incorrect use of POSIX hard links to prevent the creation of setuid executables in "the store".
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Guixsd