Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!Close

CVE-2015-5224

Published: 23 August 2017

The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks.

Notes

AuthorNote
seth-arnold
wily and vivid are built with --disable-chfn-chsh which should
disable the vulnerable code sections
precise and trusty did not appear to have the vulnerable functions

Priority

Medium

CVSS 3 base score: 9.8

Status

Package Release Status
util-linux
Launchpad, Ubuntu, Debian
upstream
Released (2.27-rc2)
precise Not vulnerable
(code not present)
trusty Not vulnerable
(code not present)
vivid Not vulnerable

wily Not vulnerable

Patches:
upstream: https://github.com/karelzak/util-linux/commit/bde91c85bdc77975155058276f99d2e0f5eab5a9