First published: Thu Oct 17 2019(Updated: )
GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Guix System Distribution | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18192 has a medium severity rating as it allows local users to access arbitrary user accounts.
To fix CVE-2019-18192, ensure that the parent directory of user-profile directories is not world writable.
Users of GNU Guix version 1.0.1 are potentially affected by CVE-2019-18192.
CVE-2019-18192 is a local privilege escalation vulnerability.
Yes, CVE-2019-18192 is similar to CVE-2019-17365, which also involves permissions issues.