CVE-2018-13405
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The intended behavior was that the non-member can trigger creation of a directory (but not a plain file) whose group ownership is that group. The non-member can escalate privileges by making the plain file executable and SGID.
Affected (92)
Show all products
Linux: Linux Kernel · Debian: Debian Linux · Canonical: Ubuntu Linux · Fedoraproject: Fedora · Redhat: Enterprise Linux Aus, Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux For Real Time, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Tus, Enterprise Linux Workstation, Mrg Realtime, Virtualization · F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Webaccelerator
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.16 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.04 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 34 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.4 | |
| Version 6.0 | |
| Version 7.4 | |
| Version 7 | |
| Version 6.0 | |
| Version 6.6 | |
| Version 7.2 | |
| Version 6.0 | |
| Version 2.0 | |
| Version 4.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 13.0.0 to 13.1.3.5 | |
| From 13.0.0 to 13.1.3.5 | |
| From 13.0.0 to 13.1.3.5 | |
| From 13.0.0 to 13.1.3.5 | |
| From 13.0.0 to 13.1.3.5 | |
| From 13.0.0 to 13.1.3.5 | |
| From 13.0.0 to 13.1.3.5 | |
| From 13.0.0 to 13.1.3.5 | |
| From 13.0.0 to 13.1.3.5 | |
| From 13.0.0 to 13.1.3.5 | |
| From 13.0.0 to 13.1.3.5 | |
| From 13.0.0 to 13.1.3.5 | |
| From 13.0.0 to 13.1.3.5 |
References (56)
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Mailing ListPatchVendor Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Timeline
No history available yet.