peter bassill · operator
$ cve CVE-2018-1000001 JSON

CVE-2018-1000001 EXPLOIT

7.8
HIGH · CVSS 3.0 · EPSS 13.4% (pctl 96)

Patch early

A public exploit exists.

Description

In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.

Scoring

CVSS7.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS13.37% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploityes
Published2018-01-31
Last modified2026-06-17

Affected (9)

VendorProduct
canonicalubuntu linux
gnuglibc
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatvirtualization host

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD