usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging a missing call check_polkit for the KVMTest method.
References
Link | Resource |
---|---|
https://www.exploit-db.com/exploits/36820/ | Exploit Third Party Advisory VDB Entry |
https://usn.ubuntu.com/usn/usn-2576-2/ | Third Party Advisory |
https://usn.ubuntu.com/usn/usn-2576-1/ | Third Party Advisory |
https://bazaar.launchpad.net/~usb-creator-hackers/usb-creator/trunk/revision/470 | Third Party Advisory |
http://www.securityfocus.com/bid/74304 | Third Party Advisory VDB Entry |
http://www.openwall.com/lists/oss-security/2015/05/04/3 | Mailing List Third Party Advisory |
http://www.openwall.com/lists/oss-security/2015/04/22/12 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Information
Published : 2017-09-27 18:29
Updated : 2017-10-11 11:36
NVD link : CVE-2015-3643
Mitre link : CVE-2015-3643
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
canonical
- ubuntu_linux
usb-creator_project
- usb-creator