Symlink attack in policycoreutils - CVE-2018-1063
Published: March 20, 2018 / Updated: March 20, 2018
Vulnerability identifier: #VU11180
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1063
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to launch symlink attack on the target system.
The weakness exists in the /tmp and /var/tmp directories improper security restrictions when presenting the relabeling process through symlinks. A local attacker can modify the SELinux context of arbitrary files and conduct symlink attacks.
The weakness exists in the /tmp and /var/tmp directories improper security restrictions when presenting the relabeling process through symlinks. A local attacker can modify the SELinux context of arbitrary files and conduct symlink attacks.
Affected software
policycoreutils
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
How to mitigate CVE-2018-1063
Cybersecurity is currently unaware of any solutions addressing the vulnerability.