CVE-2015-1350

LOW

Description

The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program.

References

http://marc.info/?l=linux-kernel&m=142153722930533&w=2

http://www.openwall.com/lists/oss-security/2015/01/24/5

http://www.securityfocus.com/bid/76075

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=770492

https://bugzilla.redhat.com/show_bug.cgi?id=1185139

Details

Source: MITRE

Published: 2016-05-02

Updated: 2020-08-03

Type: CWE-552

Risk Information

CVSS v2.0

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3.0

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Tenable Plugins

View all (13 total)

IDNameProductFamilySeverity
132360EulerOS 2.0 SP5 : kernel (EulerOS-SA-2019-2693)NessusHuawei Local Security Checks
high
132134EulerOS 2.0 SP3 : kernel (EulerOS-SA-2019-2599)NessusHuawei Local Security Checks
high
131845EulerOS 2.0 SP2 : kernel (EulerOS-SA-2019-2353)NessusHuawei Local Security Checks
critical
124971EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1518)NessusHuawei Local Security Checks
high
101929Ubuntu 16.04 LTS : linux-hwe vulnerabilities (USN-3361-1)NessusUbuntu Local Security Checks
critical
100320SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:1360-1)NessusSuSE Local Security Checks
critical
100150SUSE SLES12 Security Update : kernel (SUSE-SU-2017:1247-1)NessusSuSE Local Security Checks
critical
97297SUSE SLES11 Security Update : kernel (SUSE-SU-2017:0494-1)NessusSuSE Local Security Checks
critical
97097SUSE SLES11 Security Update : kernel (SUSE-SU-2017:0437-1)NessusSuSE Local Security Checks
critical
96903SUSE SLES11 Security Update : kernel (SUSE-SU-2017:0333-1)NessusSuSE Local Security Checks
critical
96603SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:0181-1)NessusSuSE Local Security Checks
high
96188Debian DLA-772-1 : linux security updateNessusDebian Local Security Checks
critical
95701openSUSE Security Update : the Linux Kernel (openSUSE-2016-1426)NessusSuSE Local Security Checks
critical