CVE-2015-3643
Summary
| CVE | CVE-2015-3643 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-28 01:29:00 UTC |
| Updated | 2017-10-11 18:36:00 UTC |
| Description | usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging a missing call check_polkit for the KVMTest method. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 15.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 15.04 | All | All | All |
| Application | Usb-creator Project | Usb-creator | All | All | All | All |
| Application | Usb-creator Project | Usb-creator | All | All | All | All |
| Application | Usb-creator Project | Usb-creator | All | All | All | All |
| Application | Usb-creator Project | Usb-creator | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ~usb-creator-hackers/usb-creator/trunk : revision 470 | MISC | bazaar.launchpad.net | Third Party Advisory |
| USN-2576-2: usb-creator vulnerability | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| oss-security - USBCreator D-Bus service | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| USN-2576-1: usb-creator vulnerability | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| usb-creator 0.2.x (Ubuntu 12.04/14.04/14.10) - Privilege Escalation | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| oss-security - Re: USBCreator D-Bus service | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| usb-creator Local Authentication Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.