debian crossroads CVE-2018-18654 is a vulnerability in Debian Crossroads
Published on October 26, 2018

Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in a certain location under the /tmp directory, wait until a user process copies xr there, and then replace the entire contents of this subdirectory to include a Trojan horse xr.

NVD


Products Associated with CVE-2018-18654

Want to know whenever a new CVE is published for Debian Crossroads? stack.watch will email you.

 

Exploit Probability

EPSS
0.03%
Percentile
7.70%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.