mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-07 05:26:37 +00:00
18 lines
877 B
Markdown
18 lines
877 B
Markdown
### [CVE-2018-1000857](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000857)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
log-user-session version 0.7 and earlier contains a Directory Traversal vulnerability in Main SUID-binary /usr/local/bin/log-user-session that can result in User to root privilege escalation. This attack appear to be exploitable via Malicious unprivileged user executes the vulnerable binary/(remote) environment variable manipulation similar shell-shock also possible.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://www.halfdog.net/Security/2018/LogUserSessionLocalRootPrivilegeEscalation/
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|