CVE-2019-3461 -- tmpreaperID: oval:org.secpod.oval:def:1901963 | Date: (C)2019-05-07 (M)2023-12-20 |
Class: VULNERABILITY | Family: unix |
Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a mount via rename which could result in local privilege escalation. Mounting via rename could potentially lead to a file being placed elsewhereon the filesystem hierarchy if the directory being cleaned up was on the same physical filesystem. Fixed versions include 1.6.13+nmu1+deb9u1 and 1.6.14.
Platform: |
Ubuntu 16.04 |
Ubuntu 18.10 |
Ubuntu 18.04 |