First published: Thu Dec 20 2018(Updated: )
An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux. An untrusted search path vulnerability in the keybase-redirector application allows a local, unprivileged user on Linux to gain root privileges via a Trojan horse binary.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Keybase Keybase | <2.8.0-20181023124437 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18629 is a vulnerability in the Keybase command-line client for Linux that allows a local, unprivileged user to gain root privileges.
The CVE-2018-18629 vulnerability is an untrusted search path vulnerability in the keybase-redirector application, which allows an attacker to execute a Trojan horse binary and gain root privileges.
The severity of the CVE-2018-18629 vulnerability is high with a CVSS score of 7.8.
The Keybase command-line client versions before 2.8.0-20181023124437 for Linux are affected by CVE-2018-18629.
To fix the CVE-2018-18629 vulnerability, update the Keybase command-line client to version 2.8.0-20181023124437 or later.