Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-1327

Опубликовано: 22 апр. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 3.9

Описание

Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to the file to create a transfer. This could allow a malicious application using the DBUS API to export file:///etc/passwd which would then send a copy of that file to another app.

РелизСтатусПримечание
devel

not-affected

esm-apps/xenial

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
precise

DNE

trusty

not-affected

trusty/esm

DNE

trusty was not-affected
upstream

needs-triage

utopic

not-affected

vivid

released

0.0+15.04.20150331-0ubuntu1.0
vivid/stable-phone-overlay

released

0.1+15.04.20151216.1-0ubuntu1

Показывать по

Ссылки на источники

EPSS

Процентиль: 40%
0.00186
Низкий

4.3 Medium

CVSS2

3.9 Low

CVSS3

Связанные уязвимости

CVSS3: 3.9
nvd
почти 7 лет назад

Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to the file to create a transfer. This could allow a malicious application using the DBUS API to export file:///etc/passwd which would then send a copy of that file to another app.

CVSS3: 7.8
github
больше 3 лет назад

Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to the file to create a transfer. This could allow a malicious application using the DBUS API to export file:///etc/passwd which would then send a copy of that file to another app.

EPSS

Процентиль: 40%
0.00186
Низкий

4.3 Medium

CVSS2

3.9 Low

CVSS3