← Back

CVE-2015-1336

nvd nist
Published: Sep 28, 2017Modified: May 13, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.

Affected (1)

Man Db
Configuration A
3 platform
Running on/withPlatform Versions
Canonical
Ubuntu Linux
Version 12.04
Canonical
Ubuntu Linux
Version 14.04
Canonical
Ubuntu Linux
Version 16.04
Configuration B
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Up to 2.7.6.1
Running on/withPlatform Versions
Debian
Debian Linux
Version 8.0
Debian
Debian Linux
Version 9.0

References (16)

Source: security@ubuntu.com
ExploitThird Party AdvisoryVDB Entry
Source: security@ubuntu.com
ExploitThird Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party AdvisoryVDB Entry
Source: security@ubuntu.com
Third Party AdvisoryVDB Entry
Source: security@ubuntu.com
Issue TrackingThird Party Advisory
Source: security@ubuntu.com
Issue TrackingThird Party Advisory
Source: security@ubuntu.com
Issue TrackingThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party AdvisoryVDB Entry

Timeline

No history available yet.