CVE-2015-1324
Last modified
CVE-2015-1324 is a vulnerability of currently unknown severity. Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write to arbitrary files and gain root privileges by leveraging incorrect handling of permissions when generating core dumps for setuid binaries.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write to arbitrary files and gain root privileges by leveraging incorrect handling of permissions when generating core dumps for setuid binaries.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 14.10 |
| Canonical | Ubuntu Linux | 15.04 |
References
- http://www.securityfocus.com/bid/74767Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2609-1Patch, Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1452239Issue Tracking, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/74767Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2609-1Patch, Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1452239Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-1324?
How severe is CVE-2015-1324?
How do I fix CVE-2015-1324?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-1318The crash reporting feature in Apport 2.13 through 2.17.x be…
- CVE-2015-1319The Unity Settings Daemon before 14.04.0+14.04.20150825-0ubu…
- CVE-2015-1320The SeaMicro provisioning of Ubuntu MAAS logs credentials, i…5.5
- CVE-2015-1321Use-after-free vulnerability in the file picker implementati…
- CVE-2015-1322Directory traversal vulnerability in the Ubuntu network-mana…
- CVE-2015-1323The simulate dbus method in aptdaemon before 1.1.1+bzr982-0u…
- CVE-2015-1325Race condition in Apport before 2.17.2-0ubuntu1.1 as package…
- CVE-2015-1326python-dbusmock before version 0.15.1 AddTemplate() D-Bus me…5.7
- CVE-2015-1327Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBU…3.9
- CVE-2015-1328The overlayfs implementation in the linux (aka Linux kernel)…
- CVE-2015-1329Use-after-free vulnerability in oxide::qt::URLRequestDelegat…
- CVE-2015-1330unattended-upgrades before 0.86.1 does not properly authenti…
Are you affected by CVE-2015-1324?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
