VulnerabilityModified
CVE-2018-1000001
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.
HIGH 7.8EPSS 13.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.4%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 13.37% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- gnu/glibc · canonical/ubuntu linux · redhat/virtualization host · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://seclists.org/oss-sec/2018/q1/38Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/102525Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040162Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0805Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190404-0003/
- https://usn.ubuntu.com/3534-1/Third Party Advisory
- https://usn.ubuntu.com/3536-1/Third Party Advisory
- https://www.exploit-db.com/exploits/43775/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44889/Exploit, Third Party Advisory, VDB Entry
- https://www.halfdog.net/Security/2017/LibcRealpathBufferUnderflow/Third Party Advisory
- http://seclists.org/oss-sec/2018/q1/38Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/102525Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040162Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0805Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190404-0003/
- https://usn.ubuntu.com/3534-1/Third Party Advisory
- https://usn.ubuntu.com/3536-1/Third Party Advisory
- https://www.exploit-db.com/exploits/43775/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44889/Exploit, Third Party Advisory, VDB Entry
- https://www.halfdog.net/Security/2017/LibcRealpathBufferUnderflow/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.