#VU15168 Integer overflow


Published: 2020-03-18 | Updated: 2021-06-17

Vulnerability identifier: #VU15168

Vulnerability risk: Low

CVSSv3.1:

CVE-ID: CVE-2018-14634

CWE-ID: CWE-190

Exploitation vector: Local

Exploit availability: Yes

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to integer overflow in create_elf_tables() function when processing SUID binaries. A local unprivileged user can use this vulnerability to execute execute arbitrary code on the system with elevated privileges.

Mitigation
Install updates from vendor's website.

External links
http://access.redhat.com/errata/RHSA-2018:2748
http://access.redhat.com/errata/RHSA-2018:2763
http://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14634
http://usn.ubuntu.com/3775-1/
http://usn.ubuntu.com/3775-2/
http://usn.ubuntu.com/3779-1/
http://www.exploit-db.com/exploits/45516/
http://www.openwall.com/lists/oss-security/2018/09/25/4


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability