ISOMAN

CVE

CVE-2015-1336

The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.

Severity
HIGH
CVSS
7.8
Published
Modified

Linked Releases

References

  1. http://packetstormsecurity.com/files/140759/Man-db-2.6.7.1-Privilege-Escalation.html
  2. http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1336.html
  3. http://www.halfdog.net/Security/2015/MandbSymlinkLocalRootPrivilegeEscalation/
  4. http://www.openwall.com/lists/oss-security/2015/12/14/11
  5. http://www.securityfocus.com/bid/79723
  6. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=840357
  7. https://bugs.launchpad.net/ubuntu/+source/man-db/+bug/1482786
  8. https://security.gentoo.org/glsa/201707-12
  9. http://packetstormsecurity.com/files/140759/Man-db-2.6.7.1-Privilege-Escalation.html
  10. http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1336.html
  11. http://www.halfdog.net/Security/2015/MandbSymlinkLocalRootPrivilegeEscalation/
  12. http://www.openwall.com/lists/oss-security/2015/12/14/11
  13. http://www.securityfocus.com/bid/79723
  14. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=840357
  15. https://bugs.launchpad.net/ubuntu/+source/man-db/+bug/1482786
  16. https://security.gentoo.org/glsa/201707-12