First published: Mon Sep 25 2017(Updated: )
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Elasticsearch Logstash | =5.0.0 | |
Elasticsearch Logstash | =5.0.1 | |
Elasticsearch Logstash | =5.0.2 | |
Elasticsearch Logstash | =5.1.1 | |
Elasticsearch Logstash | =5.1.2 | |
Elasticsearch Logstash | =5.2.0 | |
Elasticsearch Logstash | =5.2.1 | |
Elasticsearch Logstash | =5.3.0 | |
Elasticsearch Logstash | =5.3.1 | |
Elasticsearch Logstash | =5.3.2 | |
Elasticsearch Logstash | =5.4.1 | |
Elasticsearch Logstash | =5.4.2 | |
Elasticsearch Logstash | =5.4.3 | |
Elasticsearch Logstash | =5.5.0 | |
Elasticsearch Logstash | =5.5.1 | |
Elasticsearch Logstash | =5.5.2 | |
Elasticsearch Logstash | =5.6.0 | |
Gentoo Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.