CVE-2013-2207

Description

pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.

Risk Information

Base Score
7.1
MODERATE
Vector
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.071

Associated Vulnerability

VulnerabilityOS Platform
GNU C Library (USN-2985-1) libc6_2.19-0ubuntu6.8_i386.debLinux
GNU C Library (USN-2985-1) libc6_2.19-0ubuntu6.8_amd64.debLinux
GNU C Library (USN-2985-1) libc6_2.21-0ubuntu4.2_i386.debLinux
GNU C Library (USN-2985-1) libc6_2.21-0ubuntu4.2_amd64.debLinux
GNU C Library (USN-2985-1) libc6_2.15-0ubuntu10.14_i386.debLinux
GNU C Library (USN-2985-1) libc6_2.15-0ubuntu10.14_amd64.debLinux
GNU C Library (USN-2985-1) libc6-dev_2.19-0ubuntu6.8_i386.debLinux
GNU C Library (USN-2985-1) libc6-dev_2.19-0ubuntu6.8_amd64.debLinux
GNU C Library (USN-2985-1) libc6-dev_2.21-0ubuntu4.2_i386.debLinux
GNU C Library (USN-2985-1) libc6-dev_2.21-0ubuntu4.2_amd64.debLinux
GNU C Library (USN-2985-1) libc6-dev_2.15-0ubuntu10.14_i386.debLinux
GNU C Library (USN-2985-1) libc6-dev_2.15-0ubuntu10.14_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234