7.2
CVSSv2

CVE-2015-5228

Published: 07/06/2016 Updated: 30/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing files via unspecified vectors related to a directory path.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.2

criu checkpoint\\/restore in userspace -

Vendor Advisories

Debian Bug report logs - #797111 criu: CVE-2015-5228: arbitrary file creation and chown Package: src:criu; Maintainer for src:criu is Salvatore Bonaccorso <carnil@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 27 Aug 2015 20:39:06 UTC Severity: important Tags: security, upstream Found ...
The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing files via unspecified vectors related to a directory path ...