CVE-2015-1815
Publication date 30 March 2015
Last updated 24 July 2024
Ubuntu priority
Description
The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| sepolgen | ||
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
|
Notes
sbeattie
failure to sanitize an rpm command, passed into dbus service not likely to matter on debian/ubuntu