CVE-2017-18367
libseccomp-golang: mishandling of multiple argument rules leading to a bypass of intended access restrictions
Severity Score
7.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single matching argument.
libseccomp-golang versión 0.9.0 y anteriores, BPF generan incorrectamente múltiples argumentos OR en lugar de ANDing. Un proceso que se realiza bajo un filtro seccomp restrictivo que especificó múltiples argumentos de syscall podría omitir las restricciones de acceso previstas al especificar un único argumento coincidente.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-04-24 CVE Reserved
- 2019-04-24 CVE Published
- 2024-08-05 CVE Updated
- 2024-09-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-305: Authentication Bypass by Primary Weakness
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2020/08/msg00016.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:4087 | 2020-10-14 | |
https://access.redhat.com/errata/RHSA-2019:4090 | 2020-10-14 | |
https://usn.ubuntu.com/4574-1 | 2020-10-14 | |
https://access.redhat.com/security/cve/CVE-2017-18367 | 2020-06-18 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1706826 | 2020-06-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Libseccomp-golang Project Search vendor "Libseccomp-golang Project" | Libseccomp-golang Search vendor "Libseccomp-golang Project" for product "Libseccomp-golang" | <= 0.9.0 Search vendor "Libseccomp-golang Project" for product "Libseccomp-golang" and version " <= 0.9.0" | - |
Affected
|