CVE-2017-18018

EUVD-2017-9158
In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA-ADPADP
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
Affected Products (NVD)
VendorProductVersion
gnucoreutils
𝑥
≤ 8.29
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
coreutils
bookworm
unimportant
bullseye
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
coreutils
artful
ignored
bionic
ignored
cosmic
ignored
disco
ignored
eoan
ignored
focal
not-affected
groovy
ignored
hirsute
ignored
impish
not-affected
jammy
not-affected
trusty
ignored
xenial
ignored
zesty
ignored