Vulnerability identifier: #VU15168
Vulnerability risk: Low
CVSSv3.1:
CVE-ID:
CWE-ID:
CWE-190
Exploitation vector: Local
Exploit availability: Yes
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to integer overflow in create_elf_tables() function when processing SUID binaries. A local unprivileged user can use this vulnerability to execute execute arbitrary code on the system with elevated privileges.
Mitigation
Install updates from vendor's website.
External links
http://access.redhat.com/errata/RHSA-2018:2748
http://access.redhat.com/errata/RHSA-2018:2763
http://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14634
http://usn.ubuntu.com/3775-1/
http://usn.ubuntu.com/3775-2/
http://usn.ubuntu.com/3779-1/
http://www.exploit-db.com/exploits/45516/
http://www.openwall.com/lists/oss-security/2018/09/25/4
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?