CVE-2015-1338

medium

Description

kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.

References

https://launchpad.net/apport/trunk/2.19

https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1492570

http://www.ubuntu.com/usn/USN-2744-1

http://seclists.org/fulldisclosure/2015/Sep/101

Details

Source: Mitre, NVD

Published: 2015-10-01

Updated: 2015-10-02

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium