First published: Mon Apr 13 2015(Updated: )
fts.c in coreutils 8.4 allows local users to delete arbitrary files.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Coreutils | =8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1865 is classified as a high severity vulnerability due to its potential for arbitrary file deletion.
To fix CVE-2015-1865, upgrade to a later version of coreutils that addresses the TOCTOU race condition.
CVE-2015-1865 affects GNU Coreutils version 8.4, particularly on systems using this version of the rm command.
CVE-2015-1865 involves a race condition in the rm command that could allow local users to delete arbitrary files.
Yes, CVE-2015-1865 can lead to unintentional data loss if an attacker exploits the vulnerability during recursive directory removal.