Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-15288

Опубликовано: 15 нояб. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.2
CVSS3: 7.8

Описание

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

2.11.12-2
cosmic

not-affected

2.11.12-2
devel

not-affected

2.11.12-2
disco

not-affected

2.11.12-2
eoan

not-affected

2.11.12-2
esm-apps/bionic

not-affected

2.11.12-2
esm-apps/focal

not-affected

2.11.12-2
esm-apps/jammy

not-affected

2.11.12-2
esm-apps/noble

not-affected

2.11.12-2

Показывать по

EPSS

Процентиль: 33%
0.00128
Низкий

7.2 High

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 6.7
redhat
около 8 лет назад

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.

CVSS3: 7.8
nvd
около 8 лет назад

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.

CVSS3: 7.8
debian
около 8 лет назад

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, ...

CVSS3: 7.8
github
больше 7 лет назад

High severity vulnerability that affects org.scala-lang:scala-compiler

EPSS

Процентиль: 33%
0.00128
Низкий

7.2 High

CVSS2

7.8 High

CVSS3