Vulnerability CVE-2018-6559


Published: 2018-10-26

Description:
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Linux -> Linux kernel 
Canonical -> Ubuntu linux 

 References:
http://www.securityfocus.com/bid/105752
https://launchpad.net/bugs/1793458
https://lists.ubuntu.com/archives/kernel-team/2018-October/096172.html
https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-6559.html
https://usn.ubuntu.com/3832-1/
https://usn.ubuntu.com/3833-1/
https://usn.ubuntu.com/3835-1/
https://usn.ubuntu.com/3836-1/
https://usn.ubuntu.com/3836-2/

Copyright 2024, cxsecurity.com

 

Back to Top