7.8

CVE-2018-1000001

Exploit
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnu ≫ Glibc Version <= 2.26
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.10
Redhat ≫ Virtualization Host Version 4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.37% 0.96
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://access.redhat.com/errata/RHSA-2018:0805
Third Party Advisory
http://seclists.org/oss-sec/2018/q1/38
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/102525
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1040162
Third Party Advisory
VDB Entry
https://security.netapp.com/advisory/ntap-20190404-0003/
https://usn.ubuntu.com/3534-1/
Third Party Advisory
https://usn.ubuntu.com/3536-1/
Third Party Advisory
https://www.exploit-db.com/exploits/43775/
Third Party Advisory
Exploit
VDB Entry
https://www.exploit-db.com/exploits/44889/
Third Party Advisory
Exploit
VDB Entry
https://www.halfdog.net/Security/2017/LibcRealpathBufferUnderflow/
Third Party Advisory