← Back to CVE List

CVE-2018-6954

Published: 2018-02-13T20:29Z
Last Modified: 2024-11-21T04:11Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt