SB2017061209 - Privilege escalation in Ubuntu 



SB2017061209 - Privilege escalation in Ubuntu

Published: June 13, 2017 Updated: June 27, 2017

Security Bulletin ID SB2017061209
Severity
Low
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Privilege escalation (CVE-ID: CVE-2017-9525)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists in Cron due to a flaw in the postinst maintainer script. A local attacker with crontab group privileges can conduct a symlink attack, bypass crontab privilege separation controls and gain root privileges on the target system.

Successful exploitation of the vulnerability results in privilege escalation.

Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.