| Vulnerability Name: | CVE-2018-6559 (CCN-152030) | ||||||||||||||||||||||||||||||||
| Assigned: | 2018-09-20 | ||||||||||||||||||||||||||||||||
| Published: | 2018-09-20 | ||||||||||||||||||||||||||||||||
| Updated: | 2019-10-09 | ||||||||||||||||||||||||||||||||
| Summary: | The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace. | ||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2018-6559 Source: BID Type: Third Party Advisory, VDB Entry 105752 Source: CCN Type: BID-105752 Linux Kernel CVE-2018-6559 Local Information Disclosure Vulnerability Source: CCN Type: Launchpad Bug #1793458 Overlayfs in user namespace leaks directory content of inaccessible directories Source: XF Type: UNKNOWN linux-kernel-cve20186559-info-disc(152030) Source: CONFIRM Type: Exploit, Issue Tracking, Third Party Advisory https://launchpad.net/bugs/1793458 Source: CONFIRM Type: Third Party Advisory https://lists.ubuntu.com/archives/kernel-team/2018-October/096172.html Source: CONFIRM Type: Third Party Advisory https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-6559.html Source: UBUNTU Type: Third Party Advisory USN-3832-1 Source: UBUNTU Type: Third Party Advisory USN-3833-1 Source: UBUNTU Type: Third Party Advisory USN-3835-1 Source: UBUNTU Type: Third Party Advisory USN-3836-1 Source: UBUNTU Type: Third Party Advisory USN-3836-2 Source: CCN Type: Ubuntu Web site Ubuntu Source: CCN Type: WhiteSource Vulnerability Database CVE-2018-6559 | ||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||