CVE-2018-4182

개요

A Sandbox bypass has been discovered in cups on macOS due to insecure error handling. An attacker that has obtained sandboxed root access can use this flow to escape the sandbox.

내용

This issue did not affect the versions of cups as shipped with Red Hat Enterprise Linux as cups on Linux does not support the Sandbox feature.

CVSS (Common Vulnerability Scoring System) 점수 세부 사항

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

다음의 CVSS 지표 및 점수는 예비 정보로 검토 대상입니다.

CVSS v3 점수 분석

Red HatNVDcve.org
기본 점수78.2N/A
공격 벡터LocalLocalN/A
공격 복잡성HighLowN/A
필요한 권한LowHighN/A
사용자 상호 작용NoneNoneN/A
범위UnchangedChangedN/A
기밀성HighHighN/A
무결성에 미치는 영향HighHighN/A
가용성에 미치는 영향HighHighN/A

벡터

Red Hat: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

NVD: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

취약점 이해 (CWE)

Confidentiality,Integrity,Availability,Access Control

Technical Impact: Gain Privileges or Assume Identity; Execute Unauthorized Code or Commands; Read Application Data; DoS: Crash, Exit, or Restart

An attacker will be able to gain access to any resources that are allowed by the extra privileges. Common results include executing code, disabling services, and reading restricted data. New weaknesses can be exposed because running with extra privileges, such as root or Administrator, can disable the normal security checks being performed by the operating system or surrounding environment. Other pre-existing weaknesses can turn into security vulnerabilities if they occur while operating at raised privileges.

자주하는 질문

에라타 알림을 받으시겠습니까? 여기에서 등록하세요.