CVE-2017-18018: Race Condition
Published Jan 4, 2018
·Updated
In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.
Affected Software
1 affected component
GNU Coreutils<=8.29
Event History
Jan 4, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Data Sourced
via NVD·04:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-18018?
CVE-2017-18018 has a moderate severity due to its potential to allow local users to escalate privileges.
2
How do I fix CVE-2017-18018?
To fix CVE-2017-18018, upgrade to GNU Coreutils version 8.30 or later.
3
What type of attack does CVE-2017-18018 enable?
CVE-2017-18018 enables local users to exploit a race condition to change the ownership of any file.
4
Which versions of GNU Coreutils are affected by CVE-2017-18018?
Versions of GNU Coreutils from 8.29 and earlier are affected by CVE-2017-18018.
5
Are there any workarounds for CVE-2017-18018?
Currently, there are no effective workarounds for CVE-2017-18018 aside from updating to a patched version.