PT-2018-5222 · Gnu · Guixsd

Ludovic Courtã¨S

·

Published

2018-01-02

·

Updated

2018-01-30

·

CVE-2017-1000455

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GuixSD versions prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d
Description The issue arises from the incorrect use of POSIX hard links, resulting in the creation of setuid executables in "the store". This violates a fundamental security assumption of GNU Guix, potentially leading to security breaches.
Recommendations For GuixSD versions prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d, update to a version that includes the fix for the incorrect use of POSIX hard links to prevent the creation of setuid executables in "the store".

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1000455

Affected Products

Guixsd