Description
The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or assume super-user privileges on the local client host.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-17315 | The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or assume super-user privileges on the local client host. |
References
History
No history.
Status: PUBLISHED
Assigner: f5
Published:
Updated: 2024-09-17T02:31:29.055Z
Reserved: 2018-01-12T00:00:00.000Z
Link: CVE-2018-5546
No data.
Status : Modified
Published: 2018-08-17T12:29:00.410
Modified: 2024-11-21T04:09:02.717
Link: CVE-2018-5546
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD