436
VMScore

CVE-2015-1323

Published: 21/07/2017 Updated: 25/07/2017
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

The simulate dbus method in aptdaemon prior to 1.1.1+bzr982-0ubuntu3.1 as packaged in Ubuntu 15.04, prior to 1.1.1+bzr980-0ubuntu1.1 as packaged in Ubuntu 14.10, prior to 1.1.1-1ubuntu5.2 as packaged in Ubuntu 14.04 LTS, prior to 0.43+bzr805-0ubuntu10 as packaged in Ubuntu 12.04 LTS allows local users to obtain sensitive information, or access files with root permissions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 15.04

canonical ubuntu linux 14.04

canonical ubuntu linux 14.10

canonical ubuntu linux 12.04

Vendor Advisories

Debian Bug report logs - #789162 aptdaemon: CVE-2015-1323: information disclosure via simulate dbus method Package: src:aptdaemon; Maintainer for src:aptdaemon is Julian Andres Klode <jak@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 18 Jun 2015 12:36:02 UTC Severity: grave Tags: jessi ...
Aptdaemon could be made to expose sensitive information, or allow file access as the administrator ...

Exploits

aptdaemon versions prior to 111 suffer from a file existence disclosure vulnerability ...