PT-2017-6652 · Openhpi+2 · Openhpi+2

Kurt Seifried

·

Published

2015-11-19

·

Updated

2023-02-12

·

CVE-2015-3248

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenHPI versions prior to 3.6.0
Description The issue allows local users to cause a denial of service due to disk consumption by filling the filesystem hosting /var/lib. This is possible because the /var/lib/openhpi directory has world-writable permissions. A local user could use this flaw to view, modify, and delete OpenHPI-related data, or fill up the storage device hosting the /var/lib directory.
Recommendations For versions prior to 3.6.0, update to version 3.6.0 or later to resolve the issue. As a temporary workaround, consider restricting write access to the /var/lib/openhpi directory to prevent unauthorized modifications and minimize the risk of disk consumption.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CESA-2015_2369
CVE-2015-3248
RHSA-2015:2369
RHSA-2015_2369

Affected Products

Centos
Openhpi
Red Hat