#VU15790 Permissions, Privileges, and Access Controls in Keepalived - CVE-2018-19045


Vulnerability identifier: #VU15790

Vulnerability risk: Low

CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2018-19045

CWE-ID: CWE-264

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Keepalived
Server applications / Other server solutions

Vendor: Keepalived

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to software sets insecure default permissions (0666) when creating new temporary files upon a call to PrintData or PrintStats. A local user can read potentially sensitive information from temporary files.


Mitigation
Install updates from vendor's website.

Vulnerable software versions

Keepalived: 2.0.8


External links
https://bugzilla.suse.com/show_bug.cgi?id=1015141
https://github.com/acassen/keepalived/commit/5241e4d7b177d0b6f073cfc9ed5444bf51ec89d6
https://github.com/acassen/keepalived/commit/c6247a9ef2c7b33244ab1d3aa5d629ec49f0a067
https://github.com/acassen/keepalived/issues/1048


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability