An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escalation to delete arbitrary files.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-18440 An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escalation to delete arbitrary files.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: trellix

Published:

Updated: 2024-08-05T06:10:11.241Z

Reserved: 2018-02-06T00:00:00

Link: CVE-2018-6693

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-09-18T21:29:04.183

Modified: 2024-11-21T04:11:06.833

Link: CVE-2018-6693

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses