CVE-2018-0492: Race Condition
Published Apr 3, 2018
·Updated
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.
Affected Software
5 affected componentsFixes available
debian/beep
1.4.9-11.4.9-1.1
Beep Project Beep<=1.3.4
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Apr 3, 2018
Data Sourced
via Debian·04:45 AM
SeverityAffected Software
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0492?
CVE-2018-0492 has been classified as a high severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2018-0492?
To mitigate CVE-2018-0492, upgrade to beep version 1.4.9-1 or 1.4.9-1.1.
3
Which software is affected by CVE-2018-0492?
CVE-2018-0492 affects beep versions up to and including 1.3.4 on Debian systems.
4
Can CVE-2018-0492 be exploited remotely?
CVE-2018-0492 is a local privilege escalation vulnerability and cannot be exploited remotely.
5
What platforms are impacted by CVE-2018-0492?
CVE-2018-0492 impacts Debian GNU/Linux versions 7.0, 8.0, and 9.0.