VDB
CVE-2015-0794
CVE-2015-0794
PUBLISHED
CVSS 3.5999999046325684 LOW
modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracut_block_uuid.map.
EPSS 0.35% · 26.3th percentile
Risk Scores
CVSS 2.0
3.5999999046325684
EPSS Score
0.35%
26.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| dracut_project | dracut | 0 |
| n/a | n/a | n/a |
Timeline
- Nov 19, 2015 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 29, 2023 EPSS Score
References
- [opensuse-bugs] 20150619 [Bug 935338] VUL-0: CVE-2015-0794: dracut: uses hardcoded /tmp/dracut_block_uuid.map filename - symlink attack mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2015-0794 advisory
- http://lists.opensuse.org/opensuse-bugs/2015-06/msg02580.html technical
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00098.html technical