9.3
CVSSv2

CVE-2016-6299

Published: 14/04/2017 Updated: 13/02/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The scm plug-in in mock might allow malicious users to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 25

fedoraproject fedora 24

fedoraproject fedora 23

mock project scm plugin -

Vendor Advisories

Debian Bug report logs - #850320 mock: CVE-2016-6299: privilige escalation via mock-scm Package: src:mock; Maintainer for src:mock is Tzafrir Cohen <tzafrir@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 5 Jan 2017 21:00:12 UTC Severity: grave Tags: patch, security, upstream Found in ...