CVE-2015-2285: High severity ubuntu vulnerability
Published Mar 12, 2015
·Updated
The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu Vivid 15.04, allows local users to execute arbitrary commands and gain privileges via a crafted file in /run/user//upstart/sessions/.
Affected Software
2 affected components
Ubuntu upstart<=1.13.2-0ubuntu7
Ubuntu Vivid=15.04
Event History
Mar 12, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2285?
CVE-2015-2285 is classified as a high-severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2015-2285?
To fix CVE-2015-2285, update the Upstart package to version 1.13.2-0ubuntu9 or later.
3
Who is affected by CVE-2015-2285?
CVE-2015-2285 affects local users on systems running Ubuntu Vivid 15.04 with the upstart package prior to version 1.13.2-0ubuntu9.
4
What type of attack does CVE-2015-2285 enable?
CVE-2015-2285 enables local users to execute arbitrary commands with elevated privileges.
5
When was CVE-2015-2285 disclosed?
CVE-2015-2285 was disclosed in March 2015.