Vulnerability Description
GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assumption of GNU Guix.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Guixsd | <= 0.13.0 |
Related Weaknesses (CWE)
References
- https://lists.gnu.org/archive/html/guix-devel/2017-10/msg00090.htmlIssue TrackingPatchVendor Advisory
- https://lists.gnu.org/archive/html/guix-devel/2017-10/msg00090.htmlIssue TrackingPatchVendor Advisory
FAQ
What is CVE-2017-1000455?
CVE-2017-1000455 is a vulnerability with a CVSS score of 5.5 (MEDIUM). GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assum...
How severe is CVE-2017-1000455?
CVE-2017-1000455 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-1000455?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Guixsd.