glibc: realpath() buffer underflow when getcwd() returns relative path allows privilege escalation
Published Jan 31, 2018
7.8
HIGHCVSS 3.0
EPSS 13.37%
Description
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.
Affected products
No data.
Configuration 2
- 12.04
- 14.04
- 16.04
- 17.10
Configuration 3
- 4.0
- 7.0
- 7.0
- 7.6
- 7.6
- 7.6
- 7.0
No data.
Red Hat Enterprise Linux 7
glibc-0:2.17-222.el7
Fixed · RHSA-2018:0805
Red Hat Enterprise Linux 5
compat-glibc
Not affected
Red Hat Enterprise Linux 5
glibc
Not affected
Red Hat Enterprise Linux 6
compat-glibc
Not affected
Red Hat Enterprise Linux 6
glibc
Will not fix
Red Hat Enterprise Linux 7
compat-glibc
Not affected
Red Hat Enterprise Linux 8
glibc
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | glibc-0:2.17-222.el7 | Fixed | RHSA-2018:0805 |
| Red Hat Enterprise Linux 5 | compat-glibc | Not affected | n/a |
| Red Hat Enterprise Linux 5 | glibc | Not affected | n/a |
| Red Hat Enterprise Linux 6 | compat-glibc | Not affected | n/a |
| Red Hat Enterprise Linux 6 | glibc | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | compat-glibc | Not affected | n/a |
| Red Hat Enterprise Linux 8 | glibc | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability affected the glibc package on Red Hat Enterprise Linux 7.4, however it can only be exploited when mount namespaces owned by user namespaces are enabled, which requires manually configuring a kernel parameter and sysctl that are not enabled by default. Please see the Bugzilla link for more details. This vulnerability affects glibc on Red Hat Enterprise Linux 6. However the kernel included in Red Hat Enterprise Linux 6 does not violate glibc's assumption about the behaviour of getcwd(), so this vulnerability can not be exploited when running with the default kernel. Red Hat Enterprise Linux 6 containers may be vulnerable when running on a host with kernel 2.6.36 or greater.
References (14)
- http://seclists.org/oss-sec/2018/q1/38 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/102525 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040162 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:0805 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-1000001 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1533836 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000001
- https://security.netapp.com/advisory/ntap-20190404-0003/ x_refsource_CONFIRM
- https://usn.ubuntu.com/3534-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3536-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-1000001
- https://www.exploit-db.com/exploits/43775/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/44889/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.halfdog.net/Security/2017/LibcRealpathBufferUnderflow/ x_refsource_MISCThird Party Advisory
Change history (0)
No recorded changes yet.