First published: Thu Mar 12 2015(Updated: )
The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu Vivid 15.04, allows local users to execute arbitrary commands and gain privileges via a crafted file in /run/user/*/upstart/sessions/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | <=1.13.2-0ubuntu7 | |
Ubuntu | =15.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2285 is classified as a high-severity vulnerability due to its potential for privilege escalation.
To fix CVE-2015-2285, update the Upstart package to version 1.13.2-0ubuntu9 or later.
CVE-2015-2285 affects local users on systems running Ubuntu Vivid 15.04 with the upstart package prior to version 1.13.2-0ubuntu9.
CVE-2015-2285 enables local users to execute arbitrary commands with elevated privileges.
CVE-2015-2285 was disclosed in March 2015.