The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or assume super-user privileges on the local client host.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-17315 The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or assume super-user privileges on the local client host.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published:

Updated: 2024-09-17T02:31:29.055Z

Reserved: 2018-01-12T00:00:00

Link: CVE-2018-5546

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-17T12:29:00.410

Modified: 2024-11-21T04:09:02.717

Link: CVE-2018-5546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses