PT-2015-1273 · Red Hat+1 · Setroubleshoot+2

Sebastian Krahmer

·

Published

2015-03-26

·

Updated

2023-02-13

·

CVE-2015-1815

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions setroubleshoot versions prior to 3.2.22
Description The issue is related to incorrect file name handling, which can be exploited by remote attackers to execute arbitrary commands by adding shell metacharacters to file names. This is specifically related to the get rpm nvr by file path temporary function in util.py.
Recommendations For versions prior to 3.2.22, update to version 3.2.22 or later to resolve the issue. As a temporary workaround, consider restricting access to the get rpm nvr by file path temporary function in util.py until a patch is available.

Exploit

Fix

RCE

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2015-10303
CESA-2015_0729
CVE-2015-1815
RHSA-2015:0729
RHSA-2015_0729

Affected Products

Centos
Red Hat
Setroubleshoot