CVE-2019-17365: High severity nixos vulnerability
Published Oct 9, 2019
·Updated
Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.
Affected Software
2 affected components
NixOS Nix<=2.3
NixOS Nix<=2.3
Event History
Oct 9, 2019
CVE Published
via MITRE·09:19 PM
Data Sourced
via MITRE·09:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17365?
CVE-2019-17365 has a medium severity level, as it allows local users to gain unauthorized access to other user accounts.
2
How do I fix CVE-2019-17365?
To fix CVE-2019-17365, ensure that the parent directory of user-profile directories is not world writable.
3
Who is affected by CVE-2019-17365?
Users of Nix versions up to and including 2.3 are affected by CVE-2019-17365.
4
What type of vulnerability is CVE-2019-17365?
CVE-2019-17365 is a local privilege escalation vulnerability.
5
Is there a public exploit for CVE-2019-17365?
As of now, there are no known public exploits for CVE-2019-17365.