Vulnerabilities (CVE)

Filtered by vendor Gnu Subscribe
Filtered by product Coreutils
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-2781 1 Gnu 1 Coreutils 2021-02-25 2.1 LOW 6.5 MEDIUM
chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
CVE-2017-18018 1 Gnu 1 Coreutils 2018-01-19 1.9 LOW 4.7 MEDIUM
In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.
CVE-2015-1865 1 Gnu 1 Coreutils 2017-09-27 3.3 LOW 4.7 MEDIUM
fts.c in coreutils 8.4 allows local users to delete arbitrary files.