Unrated severityNVD Advisory· Published Oct 26, 2018· Updated Sep 16, 2024
CVE-2018-18654
CVE-2018-18654
Description
Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in a certain location under the /tmp directory, wait until a user process copies xr there, and then replace the entire contents of this subdirectory to include a Trojan horse xr.
Affected products
1- Range: =2.81
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- bugs.debian.org/911877mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.