CVE-2019-18192

NameCVE-2019-18192
DescriptionGNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
guix (PTS)bullseye1.2.0-4+deb11u2fixed
bullseye (security)1.2.0-4+deb11u3fixed
bookworm1.4.0-3+deb12u1fixed
bookworm (security)1.4.0-3+deb12u2fixed
sid1.4.0-8fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
guixsource(unstable)(not affected)

Notes

- guix <not-affected> (Fixed before initial upload to Debian)
https://issues.guix.gnu.org/issue/37744
https://git.savannah.gnu.org/cgit/guix.git/commit/?id=81c580c8664bfeeb767e2c47ea343004e88223c7 (v1.1.0rc1)

Search for package or bug name: Reporting problems