Vulnerability Name: | CVE-2015-1328 (CCN-103882) | ||||||||||||||||||||
Assigned: | 2015-06-16 | ||||||||||||||||||||
Published: | 2015-06-16 | ||||||||||||||||||||
Updated: | 2017-09-21 | ||||||||||||||||||||
Summary: | The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace. | ||||||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
| ||||||||||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.9 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
5.9 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-1328 Source: CCN Type: Pivotal Web site CVE-2015-1328 - overlayfs privilege escalation Source: CCN Type: oss-security Mailing List, Tue, 16 Jun 2015 09:17:28 +0900 CVE-2015-1328: incorrect permission checks in overlayfs, ubuntu local root Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20150616 CVE-2015-1328: incorrect permission checks in overlayfs, ubuntu local root Source: EXPLOIT-DB Type: Exploit, VDB Entry 40688 Source: BID Type: Third Party Advisory, VDB Entry 75206 Source: XF Type: UNKNOWN ubuntu-overlayfs-priv-esc(103882) Source: CCN Type: Ubuntu GIT Repository UBUNTU: SAUCE: Overlayfs: allow unprivileged mounts Source: CCN Type: Packet Storm Security [06-16-2015] Ubuntu 12.04 / 14.04 / 14.10 / 15.04 overlayfs Local Root Source: CCN Type: Packet Storm Security [11-01-2016] Overlayfs Privilege Escalation Source: CONFIRM Type: Vendor Advisory https://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1328.html Source: CONFIRM Type: Third Party Advisory https://security-tracker.debian.org/tracker/CVE-2015-1328 Source: EXPLOIT-DB Type: UNKNOWN 37292 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [06-16-2015] Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [11-02-2016] | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |