Privilege escalation in Scala - CVE-2017-15288

 

Privilege escalation in Scala - CVE-2017-15288

Published: December 15, 2018 / Updated: December 17, 2018


Vulnerability identifier: #VU16559
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15288
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The vulnerability exists due to the compilation daemon uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port. A local attacker can write to arbitrary class files and consequently gain privileges.


Affected software

Scala
Gentoo Linux
Dell Support Assist Enterprise
IBM Cloud Application Performance Management (APM)

How to mitigate CVE-2017-15288

The vulnerability has been fixed in the versions 2.10.7, 2.11.12, 2.12.4.

Scala - addressed in versions 2.10.7, 2.11.12, 2.12.4
Dell Support Assist Enterprise - update to 4.00.06.00
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14

External References

Related Security Bulletins