CVE-2015-1328
CVE-2015-1328
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 13
githubgithub.com/elit3pwner/CVE-2015-1328-GoldenEye★ 10githubgithub.com/0xf1d0/CVE-2015-1328★ 1githubgithub.com/SR7-HACKING/LINUX-VULNERABILITY-CVE-2015-1328★ 0githubgithub.com/notlikethis/CVE-2015-1328★ 0githubgithub.com/saqib-butt2/blackbox-pentesting-infsecos★ 0githubgithub.com/BlackFrog-hub/cve-2015-1328★ 0githubgithub.com/YastrebX/CVE-2015-1328★ 0githubgithub.com/thieveshkar/RootQuest-CTF-Box-Multi-Stage-Exploitation-VM★ 0exploitdbwww.exploit-db.com/exploits/37293não verificadocve_referencewww.exploit-db.com/exploits/40688/não verificadoexploitdbwww.exploit-db.com/exploits/40688não verificadoexploitdbwww.exploit-db.com/exploits/37292não verificadocve_referencewww.exploit-db.com/exploits/37292/não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://seclists.org/oss-sec/2015/q2/717https://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1328.htmlhttps://security-tracker.debian.org/tracker/CVE-2015-1328https://www.exploit-db.com/exploits/37292/http://www.exploit-db.com/exploits/40688/http://www.securityfocus.com/bid/75206