CVE-2015-1795
published 2017-06-27CVE-2015-1795: Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
PriorityP340high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.46%
36.8th percentile
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glusterfs | — | — |
| redhat | gluster_storage | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vq9q-mjvr-qpfx: Red Hat Gluster Storage RPM Package 3
ghsa_unreviewed·2022-05-14
CVE-2015-1795 [HIGH] GHSA-vq9q-mjvr-qpfx: Red Hat Gluster Storage RPM Package 3
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
Red Hat
glusterfs: glusterfs-server %pretrans rpm script temporary file issue
vendor_redhat·2015-03-16·CVSS 7.8
CVE-2015-1795 [HIGH] CWE-377 glusterfs: glusterfs-server %pretrans rpm script temporary file issue
glusterfs: glusterfs-server %pretrans rpm script temporary file issue
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
It was found that glusterfs-server RPM package would write file with predictable name into world readable /tmp directory. A local attacker could potentially use this flaw to escalate their privileges to root by modifying the shell script during the installation of the glusterfs-server package.
Statement: This issue did not affect the versions of glusterfs as shipped
with Red Hat Enterprise Linux 6, and 7.
Package: glusterfs (Red Hat Enterprise Linux 6) - Not affected
Package: glusterfs (Red Hat Storage 2.1) - Will not fix
Debian
CVE-2015-1795: glusterfs - Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges an...
vendor_debian·2015·CVSS 7.8
CVE-2015-1795 [HIGH] CVE-2015-1795: glusterfs - Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges an...
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2017-0484.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0486.htmlhttp://www.securityfocus.com/bid/99311http://www.securitytracker.com/id/1038128https://bugzilla.redhat.com/show_bug.cgi?id=1200927http://rhn.redhat.com/errata/RHSA-2017-0484.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0486.htmlhttp://www.securityfocus.com/bid/99311http://www.securitytracker.com/id/1038128https://bugzilla.redhat.com/show_bug.cgi?id=1200927
2017-06-27
Published