First published: Mon Oct 26 2020(Updated: )
opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openr Opentmpfiles | <=0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18925 has a medium severity rating due to its potential to allow local users to compromise file ownership.
To fix CVE-2017-18925, ensure that you update opentmpfiles to version 0.3.2 or later, which addresses the vulnerability.
Local users with access to systems running opentmpfiles versions 0.3.1 or earlier are affected by CVE-2017-18925.
CVE-2017-18925 is a local file ownership vulnerability that arises from improper handling of directory entries, allowing a symlink attack.
No, CVE-2017-18925 can only be exploited locally by users with access to the affected system.