pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.
CVSS Details
- CVSS 3.1 Base Score: 7.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade glibc | Jul 30, 2024 | Oct 9, 2013 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | Oct 9, 2013 |
| Suse | — | Upgrade glibc-32bitUpgrade glibc-profile-32bitUpgrade glibc-extraUpgrade glibc-infoUpgrade glibc-x86Upgrade glibc-profileUpgrade glibc-locale-x86Upgrade glibc-profile-x86Upgrade glibc-devel-staticUpgrade glibc-htmlUpgrade glibc-utils-32bitUpgrade glibc-devel-static-32bitUpgrade glibc-locale-32bitUpgrade glibc-localeUpgrade glibc-obsoleteUpgrade glibc-develUpgrade nscdUpgrade glibc-i18ndataUpgrade sle-sdk-releaseUpgrade glibc-devel-32bitUpgrade glibc-testsuiteUpgrade glibcUpgrade glibc-utils | Dec 12, 2013 | Oct 9, 2013 |
| Ubuntu | — | Upgrade libc6Upgrade libc6-dev | May 27, 2016 | Oct 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub