The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing files via unspecified vectors related to a directory path.
References
Information
Published : 2016-06-07 07:06
Updated : 2018-10-30 09:27
NVD link : CVE-2015-5228
Mitre link : CVE-2015-5228
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
opensuse
- opensuse
criu
- checkpoint\/restore_in_userspace