CVE-2017-18925: Medium severity openr opentmpfiles vulnerability
Published Oct 26, 2020
·Updated
opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack.
Affected Software
1 affected component
OpenR opentmpfiles<=0.3.1
Event History
Oct 26, 2020
CVE Published
via MITRE·05:58 PM
Data Sourced
via MITRE·05:58 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18925?
CVE-2017-18925 has a medium severity rating due to its potential to allow local users to compromise file ownership.
2
How do I fix CVE-2017-18925?
To fix CVE-2017-18925, ensure that you update opentmpfiles to version 0.3.2 or later, which addresses the vulnerability.
3
Who is affected by CVE-2017-18925?
Local users with access to systems running opentmpfiles versions 0.3.1 or earlier are affected by CVE-2017-18925.
4
What type of vulnerability is CVE-2017-18925?
CVE-2017-18925 is a local file ownership vulnerability that arises from improper handling of directory entries, allowing a symlink attack.
5
Can CVE-2017-18925 be exploited remotely?
No, CVE-2017-18925 can only be exploited locally by users with access to the affected system.