CVE-2015-1378

cmdlineopts.clp in grml-debootstrap in Debian 0.54, 0.68.x before 0.68.1, 0.7x before 0.78 is sourced without checking that the local directory is writable by non-root users.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:grml:grml-debootstrap:0.54:*:*:*:*:*:*:*
cpe:2.3:a:grml:grml-debootstrap:0.68:*:*:*:*:*:*:*
cpe:2.3:a:grml:grml-debootstrap:0.70:*:*:*:*:*:*:*
cpe:2.3:a:grml:grml-debootstrap:0.71:*:*:*:*:*:*:*
cpe:2.3:a:grml:grml-debootstrap:0.72:*:*:*:*:*:*:*
cpe:2.3:a:grml:grml-debootstrap:0.73:*:*:*:*:*:*:*
cpe:2.3:a:grml:grml-debootstrap:0.74:*:*:*:*:*:*:*
cpe:2.3:a:grml:grml-debootstrap:0.75:*:*:*:*:*:*:*
cpe:2.3:a:grml:grml-debootstrap:0.76:*:*:*:*:*:*:*
cpe:2.3:a:grml:grml-debootstrap:0.77:*:*:*:*:*:*:*

History

21 Nov 2024, 02:25

Type Values Removed Values Added
References () http://cve.killedkenny.io/cve/CVE-2015-1378 - Third Party Advisory () http://cve.killedkenny.io/cve/CVE-2015-1378 - Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2015/01/27/17 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2015/01/27/17 - Mailing List, Third Party Advisory
References () https://github.com/grml/grml-debootstrap/issues/59 - Issue Tracking, Third Party Advisory () https://github.com/grml/grml-debootstrap/issues/59 - Issue Tracking, Third Party Advisory
References () https://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1378.html - Third Party Advisory () https://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1378.html - Third Party Advisory
References () https://security-tracker.debian.org/tracker/CVE-2015-1378/ - Third Party Advisory () https://security-tracker.debian.org/tracker/CVE-2015-1378/ - Third Party Advisory

Information

Published : 2017-08-07 17:29

Updated : 2024-11-21 02:25


NVD link : CVE-2015-1378

Mitre link : CVE-2015-1378

CVE.ORG link : CVE-2015-1378


JSON object : View

Products Affected

grml

  • grml-debootstrap
CWE
CWE-264

Permissions, Privileges, and Access Controls