CVE-2015-2285

The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu Vivid 15.04, allows local users to execute arbitrary commands and gain privileges via a crafted file in /run/user/*/upstart/sessions/.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ubuntu:upstart:*:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:vivid:15.04:*:*:*:*:*:*:*

History

21 Nov 2024, 02:27

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/130587/Ubuntu-Vivid-Upstart-Privilege-Escalation.html - Exploit () http://packetstormsecurity.com/files/130587/Ubuntu-Vivid-Upstart-Privilege-Escalation.html - Exploit
References () http://seclists.org/fulldisclosure/2015/Mar/7 - Exploit () http://seclists.org/fulldisclosure/2015/Mar/7 - Exploit
References () http://www.halfdog.net/Security/2015/UpstartLogrotationPrivilegeEscalation/ - Exploit () http://www.halfdog.net/Security/2015/UpstartLogrotationPrivilegeEscalation/ - Exploit
References () https://bugs.launchpad.net/ubuntu/+source/upstart/+bug/1425685 - Exploit, Vendor Advisory () https://bugs.launchpad.net/ubuntu/+source/upstart/+bug/1425685 - Exploit, Vendor Advisory

Information

Published : 2015-03-12 14:59

Updated : 2024-11-21 02:27


NVD link : CVE-2015-2285

Mitre link : CVE-2015-2285

CVE.ORG link : CVE-2015-2285


JSON object : View

Products Affected

ubuntu

  • upstart
  • vivid
CWE
CWE-19

Data Processing Errors