Vulnerability Details CVE-2017-1000455
GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assumption of GNU Guix.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 4.4%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 2.1
Products affected by CVE-2017-1000455
-
-
-
cpe:2.3:a:gnu:guixsd:0.10.0
-
cpe:2.3:a:gnu:guixsd:0.11.0
-
cpe:2.3:a:gnu:guixsd:0.12.0
-
cpe:2.3:a:gnu:guixsd:0.13.0
-
-
-
-
-
-
-
-
cpe:2.3:a:gnu:guixsd:0.8.1
-
cpe:2.3:a:gnu:guixsd:0.8.2
-
cpe:2.3:a:gnu:guixsd:0.8.3
-
cpe:2.3:a:gnu:guixsd:0.9.0