Lucene search

K
osvGoogleOSV:CVE-2017-18367
HistoryApr 24, 2019 - 9:29 p.m.

CVE-2017-18367

2019-04-2421:29:00
Google
osv.dev
8

AI Score

6.7

Confidence

Low

EPSS

0.003

Percentile

70.0%

libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single matching argument.

AI Score

6.7

Confidence

Low

EPSS

0.003

Percentile

70.0%