Input validation error in coreutils - CVE-2016-2781

 

Input validation error in coreutils - CVE-2016-2781

Published: June 8, 2023


Vulnerability identifier: #VU77104
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2781
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escape to the parent session.

The vulnerability exists due in the chroot in GNU coreutils, when used with --userspec. A local user can escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.


Affected software

coreutils
Guardium Data Security Center (GDSC)
IBM Cloud Pak for Business Automation
Juniper Cloud Native Router
Junos cRPD

How to mitigate CVE-2016-2781

Install updates from vendor's website.

Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.21, 22.0.2.5
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

External References

Related Security Bulletins