Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-1328

Опубликовано: 28 нояб. 2016
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Высокий

Описание

The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:*:*:*:*
Версия до 15.04 (включая)
Конфигурация 2
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Версия до 3.19 (включая)

EPSS

Процентиль: 100%
0.89274
Высокий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 9 лет назад

The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.

CVSS3: 7.8
debian
около 9 лет назад

The overlayfs implementation in the linux (aka Linux kernel) package b ...

CVSS3: 7.8
github
больше 3 лет назад

The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.

EPSS

Процентиль: 100%
0.89274
Высокий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-264