Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-1336

Опубликовано: 28 сент. 2017
Источник: debian

Описание

The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
man-dbfixed2.7.6-1package
man-dbno-dsajessiepackage
man-dbno-dsawheezypackage
man-dbno-dsasqueezepackage

Примечания

  • http://www.halfdog.net/Security/2015/MandbSymlinkLocalRootPrivilegeEscalation/

  • https://bugs.launchpad.net/ubuntu/+source/man-db/+bug/1482786

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.

redhat
около 10 лет назад

The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.

CVSS3: 7.8
nvd
больше 8 лет назад

The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.

CVSS3: 7.8
github
больше 3 лет назад

The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.