Vulnerability CVE-2018-16597


Published: 2018-09-21

Description:
An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem.

Type:

CWE-863

(Incorrect Authorization)

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:C/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.9/10
6.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Complete
None
Affected software
Opensuse -> LEAP 
Netapp -> Active iq performance analytics services 
Netapp -> Element software 
Linux -> Linux kernel 

 References:
http://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.html
http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
http://www.securityfocus.com/bid/105394
https://bugzilla.suse.com/show_bug.cgi?id=1106512
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c0ca3d70e8d3cf81e2255a217f7ca402f5ed0862
https://seclists.org/bugtraq/2019/Jul/33
https://security.netapp.com/advisory/ntap-20190204-0001/
https://support.f5.com/csp/article/K22691834

Copyright 2024, cxsecurity.com

 

Back to Top