CVE-2015-1336
HIGH severity · CVSS 7.8 · Improper access control
7.8CVSS HIGH
Summary
The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)1%
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1336.htmlAdvisory
- http://www.openwall.com/lists/oss-security/2015/12/14/11Advisory
- http://www.securityfocus.com/bid/79723Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=840357Advisory
- https://bugs.launchpad.net/ubuntu/+source/man-db/+bug/1482786Advisory
- https://security.gentoo.org/glsa/201707-12Advisory
- http://packetstormsecurity.com/files/140759/Man-db-2.6.7.1-Privilege-Escalation.htmlAdvisory
- http://www.halfdog.net/Security/2015/MandbSymlinkLocalRootPrivilegeEscalation/Advisory