CVE-2018-6954 log
Source |
|
Severity | Medium |
Remote | No |
Type | Arbitrary file overwrite |
Description | systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-615 | systemd | 239.2-1 | 240.0-3 | Medium | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
08 Jan 2019 | ASA-201901-4 | AVG-615 | systemd | Medium | multiple issues |
References |
---|
https://github.com/systemd/systemd/issues/7986 https://github.com/systemd/systemd/pull/8822 |