Vulnerability Name:

CVE-2015-1865 (CCN-132406)

Assigned:2015-04-13
Published:2015-04-13
Updated:2017-09-27
Summary:fts.c in coreutils 8.4 allows local users to delete arbitrary files.
CVSS v3 Severity:4.7 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N)
4.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
3.3 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:3.3 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
1.7 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-362
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2015-1865

Source: BID
Type: Third Party Advisory, VDB Entry
76073

Source: CCN
Type: Red Hat Bugzilla – Bug 1211300
(CVE-2015-1865) CVE-2015-1865 coreutils: "time of check to time of use" race condition fts.c

Source: CONFIRM
Type: Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1211300

Source: XF
Type: UNKNOWN
gnucoreutils-cve20151865-sec-bypass(132406)

Source: CCN
Type: GNU Web site
GNU Coreutils

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2015-1865

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnu:coreutils:8.4:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:gnu:coreutils:8.4:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20151865
    V
    CVE-2015-1865
    2022-05-20
    oval:org.opensuse.security:def:32197
    P
    Security update for glibc (Moderate)
    2021-10-06
    oval:org.opensuse.security:def:33013
    P
    Security update for gd (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:32186
    P
    Security update for MozillaFirefox (Important)
    2021-09-22
    oval:org.opensuse.security:def:32185
    P
    Security update for ghostscript (Critical)
    2021-09-21
    oval:org.opensuse.security:def:33690
    P
    Security update for linuxptp (Important)
    2021-07-21
    oval:org.opensuse.security:def:32946
    P
    Security update for freeradius-server (Moderate)
    2021-06-11
    oval:org.opensuse.security:def:33651
    P
    Security update for xen (Important)
    2021-05-19
    oval:org.opensuse.security:def:32907
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:28964
    P
    Security update for MozillaFirefox (Important)
    2021-03-31
    oval:org.opensuse.security:def:32969
    P
    Security update for python36 (Important)
    2021-02-01
    oval:org.opensuse.security:def:28920
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:32273
    P
    Security update for MozillaFirefox (Important)
    2021-01-12
    oval:org.opensuse.security:def:28864
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:28815
    P
    Security update for puppet
    2020-12-01
    oval:org.opensuse.security:def:32501
    P
    dbus-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28187
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28903
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:32645
    P
    cups on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28383
    P
    Security update for rubygem-activesupport-3_2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32858
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28525
    P
    Security update for wget (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29638
    P
    Security update for coreutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28761
    P
    Security update for libqt4
    2020-12-01
    oval:org.opensuse.security:def:32407
    P
    Security update for wget (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28176
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32558
    P
    libnetpbm10 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28253
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32801
    P
    unzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28468
    P
    Security update for xorg-x11-libXrender (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29602
    P
    Security update for avahi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28609
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:28175
    P
    Security update for kernel-source (Important)
    2020-12-01
    oval:com.ubuntu.trusty:def:20151865000
    V
    CVE-2015-1865 on Ubuntu 14.04 LTS (trusty) - low.
    2017-09-20
    oval:com.ubuntu.precise:def:20151865000
    V
    CVE-2015-1865 on Ubuntu 12.04 LTS (precise) - low.
    2015-04-15
    BACK
    gnu coreutils 8.4
    gnu coreutils 8.4