7.5
CVSSv2

CVE-2015-8768

Published: 13/02/2017 Updated: 03/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote malicious users to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

click project click -

canonical ubuntu linux 14.04

canonical ubuntu linux 15.04

Vendor Advisories

Click could be made to allow malicious apps unintended access to the system ...