CVE-2018-1000001 is a critical buffer underflow vulnerability in glibc versions 2.26 and earlier, affecting products from vendors like Canonical, GNU, and Red Hat. This flaw arises from confusion in how realpath() uses getcwd(), potentially allowing an attacker to write before the destination buffer, leading to arbitrary code execution. With a CVSS score of 7.8 (High), it represents a local attack vector with low complexity, enabling high impact on confidentiality, integrity, and availability. While not on the CISA KEV list, exploit intelligence indicates readily available Metasploit modules and ExploitDB entries, suggesting a high potential for exploitation. The vulnerability has garnered significant community discussion and media coverage, further highlighting its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.26CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.