Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in a certain location under the /tmp directory, wait until a user process copies xr there, and then replace the entire contents of this subdirectory to include a Trojan horse xr.
References
Link | Resource |
---|---|
https://bugs.debian.org/911877 | Issue Tracking Mailing List Vendor Advisory |
Configurations
Information
Published : 2018-10-25 17:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-18654
Mitre link : CVE-2018-18654
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
debian
- crossroads