Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-20197
HistoryMar 26, 2021 - 12:00 a.m.

CVE-2021-20197

2021-03-2600:00:00
ubuntu.com
ubuntu.com
14
open race window
gnu binutils
arbitrary files ownership

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:P/A:N

CVSS3

6.3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS

0

Percentile

15.5%

There is an open race window when writing output in the following utilities
in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When
these utilities are run as a privileged user (presumably as part of a
script updating binaries across different users), an unprivileged user can
trick these utilities into getting ownership of arbitrary files through a
symlink.

Bugs

Notes

Author Note
mdeslaur commits below are from 2.36 branch. At some point, commits were reverted and then reinstated later on. The list below doesn’t include the added and reverted commits. These changes are quite intrusive to backport, are regression- prone and may introduce regressions in other packages. For this reason we will not be fixing this issue in stable releases.

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:P/A:N

CVSS3

6.3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS

0

Percentile

15.5%