CVE-2015-1338
Published: 24 September 2015
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.
Priority
Status
Package | Release | Status |
---|---|---|
apport Launchpad, Ubuntu, Debian |
precise |
Released
(2.0.1-0ubuntu17.10)
|
trusty |
Released
(2.14.1-0ubuntu3.15)
|
|
upstream |
Needs triage
|
|
vivid |
Released
(2.17.2-0ubuntu1.5)
|
|
wily |
Released
(2.19-0ubuntu1)
|
|
xenial |
Released
(2.19-0ubuntu1)
|
|
yakkety |
Released
(2.19-0ubuntu1)
|
|
zesty |
Released
(2.19-0ubuntu1)
|