systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2018-02-13 20:29
Updated : 2024-11-21 04:11
NVD link : CVE-2018-6954
Mitre link : CVE-2018-6954
CVE.ORG link : CVE-2018-6954
JSON object : View
Products Affected
systemd_project
- systemd
canonical
- ubuntu_linux
opensuse
- leap
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')