CVE-2015-1815

The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name.
Configurations

Configuration 1 (hide)

cpe:2.3:a:selinux:setroubleshoot:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*

History

21 Nov 2024, 02:26

Type Values Removed Values Added
References () http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154427.html - () http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154427.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154444.html - () http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154444.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/154147.html - () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/154147.html -
References () http://rhn.redhat.com/errata/RHSA-2015-0729.html - () http://rhn.redhat.com/errata/RHSA-2015-0729.html -
References () http://www.openwall.com/lists/oss-security/2015/03/26/1 - Exploit () http://www.openwall.com/lists/oss-security/2015/03/26/1 - Exploit
References () http://www.osvdb.org/119966 - () http://www.osvdb.org/119966 -
References () http://www.securityfocus.com/bid/73374 - () http://www.securityfocus.com/bid/73374 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=1203352 - Exploit () https://bugzilla.redhat.com/show_bug.cgi?id=1203352 - Exploit
References () https://bugzilla.redhat.com/show_bug.cgi?id=1206050 - Exploit () https://bugzilla.redhat.com/show_bug.cgi?id=1206050 - Exploit
References () https://github.com/stealth/troubleshooter - Exploit () https://github.com/stealth/troubleshooter - Exploit
References () https://www.exploit-db.com/exploits/36564/ - () https://www.exploit-db.com/exploits/36564/ -

Information

Published : 2015-03-30 14:59

Updated : 2024-11-21 02:26


NVD link : CVE-2015-1815

Mitre link : CVE-2015-1815

CVE.ORG link : CVE-2015-1815


JSON object : View

Products Affected

fedoraproject

  • fedora

selinux

  • setroubleshoot
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')