~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2015-3248

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2015-3248
2
 
PublicDate: 2017-09-26
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3248
5
 
 https://bugzilla.redhat.com/show_bug.cgi?id=1233520
6
 
 http://openhpi.org/Changelogs/3.6.0
7
 
Description:
8
 
 openhpi/Makefile.am in OpenHPI before 3.6.0 uses world-writable permissions
9
 
 for /var/lib/openhpi directory, which allows local users, when quotas are
10
 
 not properly setup, to fill the filesystem hosting /var/lib and cause a
11
 
 denial of service (disk consumption).
12
 
Ubuntu-Description:
13
 
Notes:
14
 
 sbeattie> directory is world-readable but not world-writable in
15
 
   debian/ubuntu.
16
 
Bugs:
17
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=789543
18
 
 http://sourceforge.net/p/openhpi/bugs/1883/
19
 
Priority: low
20
 
Discovered-by:
21
 
Assigned-to:
22
 
 
23
 
Patches_openhpi:
24
 
 upstream: http://sourceforge.net/p/openhpi/code/7638
25
 
upstream_openhpi: released (3.6.0)
26
 
precise_openhpi: ignored (reached end-of-life)
27
 
precise/esm_openhpi: needs-triage
28
 
trusty_openhpi: needs-triage
29
 
vivid_openhpi: ignored (reached end-of-life)
30
 
vivid/stable-phone-overlay_openhpi: DNE
31
 
vivid/ubuntu-core_openhpi: DNE
32
 
wily_openhpi: ignored (reached end-of-life)
33
 
xenial_openhpi: needs-triage
34
 
yakkety_openhpi: ignored (reached end-of-life)
35
 
zesty_openhpi: ignored (reached end-of-life)
36
 
artful_openhpi: needs-triage
37
 
bionic_openhpi: needs-triage
38
 
devel_openhpi: needs-triage