imPC@ndo EN

Tracker / CVE-2018-13405

CVE-2018-13405

Alta 7.8

The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The intended behavior was that the non-member can trigger creation of a directory (but not a plain file) whose group ownership is that group. The non-member can escalate privileges by making the plain file executable and SGID.

Prodotti e versioni affette

canonical ubuntu_linux
debian debian_linux
f5 big-ip_access_policy_manager
f5 big-ip_access_policy_manager · 13.0.0 → 13.1.3.5
f5 big-ip_access_policy_manager · 14.0.0 → 14.1.3.1
f5 big-ip_access_policy_manager · 15.0.0 → 15.0.1.4
f5 big-ip_advanced_firewall_manager
f5 big-ip_advanced_firewall_manager · 13.0.0 → 13.1.3.5
f5 big-ip_advanced_firewall_manager · 14.0.0 → 14.1.3.1
f5 big-ip_advanced_firewall_manager · 15.0.0 → 15.0.1.4
f5 big-ip_analytics
f5 big-ip_analytics · 13.0.0 → 13.1.3.5
f5 big-ip_analytics · 14.0.0 → 14.1.3.1
f5 big-ip_analytics · 15.0.0 → 15.0.1.4
f5 big-ip_application_acceleration_manager
f5 big-ip_application_acceleration_manager · 13.0.0 → 13.1.3.5
f5 big-ip_application_acceleration_manager · 14.0.0 → 14.1.3.1
f5 big-ip_application_acceleration_manager · 15.0.0 → 15.0.1.4
f5 big-ip_application_security_manager
f5 big-ip_application_security_manager · 13.0.0 → 13.1.3.5
f5 big-ip_application_security_manager · 14.0.0 → 14.1.3.1
f5 big-ip_application_security_manager · 15.0.0 → 15.0.1.4
f5 big-ip_domain_name_system
f5 big-ip_domain_name_system · 13.0.0 → 13.1.3.5
f5 big-ip_domain_name_system · 14.0.0 → 14.1.3.1
f5 big-ip_domain_name_system · 15.0.0 → 15.0.1.4
f5 big-ip_edge_gateway
f5 big-ip_edge_gateway · 13.0.0 → 13.1.3.5
f5 big-ip_edge_gateway · 14.0.0 → 14.1.3.1
f5 big-ip_edge_gateway · 15.0.0 → 15.0.1.4
f5 big-ip_fraud_protection_service
f5 big-ip_fraud_protection_service · 13.0.0 → 13.1.3.5
f5 big-ip_fraud_protection_service · 14.0.0 → 14.1.3.1
f5 big-ip_fraud_protection_service · 15.0.0 → 15.0.1.4
f5 big-ip_global_traffic_manager
f5 big-ip_global_traffic_manager · 13.0.0 → 13.1.3.5
f5 big-ip_global_traffic_manager · 14.0.0 → 14.1.3.1
f5 big-ip_global_traffic_manager · 15.0.0 → 15.0.1.4
f5 big-ip_link_controller
f5 big-ip_link_controller · 13.0.0 → 13.1.3.5
f5 big-ip_link_controller · 14.0.0 → 14.1.3.1
f5 big-ip_link_controller · 15.0.0 → 15.0.1.4
f5 big-ip_local_traffic_manager
f5 big-ip_local_traffic_manager · 13.0.0 → 13.1.3.5
f5 big-ip_local_traffic_manager · 14.0.0 → 14.1.3.1
f5 big-ip_local_traffic_manager · 15.0.0 → 15.0.1.4
f5 big-ip_policy_enforcement_manager
f5 big-ip_policy_enforcement_manager · 13.0.0 → 13.1.3.5
f5 big-ip_policy_enforcement_manager · 14.0.0 → 14.1.3.1
f5 big-ip_policy_enforcement_manager · 15.0.0 → 15.0.1.4
f5 big-ip_webaccelerator
f5 big-ip_webaccelerator · 13.0.0 → 13.1.3.5
f5 big-ip_webaccelerator · 14.0.0 → 14.1.3.1
f5 big-ip_webaccelerator · 15.0.0 → 15.0.1.4
fedoraproject fedora
linux linux_kernel · … → 3.16
redhat enterprise_linux_aus
redhat enterprise_linux_desktop
redhat enterprise_linux_eus
redhat enterprise_linux_for_real_time

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti