CVE-2018-0492

HIGH

Beep < 1.3.4 - Race Condition

Title source: rule

Description

Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.

Exploits (5)

exploitdb WORKING POC
by Pirhack · pythonlocallinux
https://www.exploit-db.com/exploits/44452
github WRITEUP 3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2018-0492.md
github WRITEUP 14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2018-0492.md
gitlab WORKING POC 1 stars
by Creased · poc
https://gitlab.com/Creased/cve-2018-0492
gitlab WORKING POC
by hackernix · poc
https://gitlab.com/hackernix/cve-2018-0492

Scores

CVSS v3 7.0
EPSS 0.0209
EPSS Percentile 84.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-362
Status published
Products (4)
beep_project/beep < 1.3.4
debian/debian_linux 7.0
debian/debian_linux 8.0
debian/debian_linux 9.0
Published Apr 03, 2018
Tracked Since Feb 18, 2026