5.3
CVSSv3

CVE-2015-5186

Published: 06/09/2017 Updated: 13/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Audit prior to 2.4.4 in Linux does not sanitize escape characters in filenames.

Vulnerable Product Search on Vulmon Subscribe to Product

linux audit project linux audit

Vendor Advisories

Debian Bug report logs - #795457 audit: CVE-2015-5186: log terminal emulator escape sequences handling Package: src:audit; Maintainer for src:audit is Laurent Bigonville <bigon@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 14 Aug 2015 07:15:01 UTC Severity: important Tags: fixed-upstre ...
Audit before 244 in Linux does not sanitize escape characters in filenames ...