CVE-2015-1419: Medium severity suse linux vulnerability
Published Jan 28, 2015
·Updated
Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to denyfile parsing.
Affected Software
4 affected components
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Beasts Vsftpd<=3.0.2
Vsftpd Project Vsftpd<=3.0.2
Remediation
Event History
Jan 28, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1419?
The severity of CVE-2015-1419 is classified as high due to its ability to allow remote attackers to bypass access restrictions.
2
How do I fix CVE-2015-1419?
To fix CVE-2015-1419, you should upgrade vsftpd to version 3.0.3 or later, as these versions contain patches for the vulnerability.
3
Which versions of vsftpd are affected by CVE-2015-1419?
CVE-2015-1419 affects vsftpd versions 3.0.2 and earlier.
4
Can CVE-2015-1419 be exploited remotely?
Yes, CVE-2015-1419 can be exploited remotely by attackers to bypass access restrictions.
5
What software platforms are affected by CVE-2015-1419?
CVE-2015-1419 affects openSUSE versions 13.1 and 13.2, as well as any instance of vsftpd up to version 3.0.2.