CVE-2015-0858: Low severity debian linux vulnerability
Published May 6, 2016
·Updated
Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory.
Affected Software
2 affected components
Debian Debian Linux=8.0
Tardiff Project Tardiff
Event History
May 6, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0858?
CVE-2015-0858 has a medium severity level due to its potential for local users to exploit symlink attacks.
2
How do I fix CVE-2015-0858?
To fix CVE-2015-0858, update the TarDiff package to the latest version that addresses the symlink vulnerability.
3
Which versions of TarDiff are affected by CVE-2015-0858?
TarDiff versions prior to the patch that resolves CVE-2015-0858 are susceptible to this vulnerability.
4
Can CVE-2015-0858 be exploited remotely?
CVE-2015-0858 cannot be exploited remotely as it requires local user privileges to execute the attack.
5
Is Debian Linux 8.0 affected by CVE-2015-0858?
Yes, Debian Linux 8.0 is affected by CVE-2015-0858 due to the vulnerable version of TarDiff included.