Privilege escalation in Scala - CVE-2017-15288
Published: December 15, 2018 / Updated: December 17, 2018
Vulnerability details
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists due to the compilation daemon uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port. A local attacker can write to arbitrary class files and consequently gain privileges.
Affected software
Gentoo Linux
Dell Support Assist Enterprise
IBM Cloud Application Performance Management (APM)
How to mitigate CVE-2017-15288
Dell Support Assist Enterprise - update to 4.00.06.00
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14