Lucene search

K
ubuntucveUbuntu.comUB:CVE-2016-10156
HistoryJan 23, 2017 - 12:00 a.m.

CVE-2016-10156

2017-01-2300:00:00
ubuntu.com
ubuntu.com
10

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

13.1%

A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid
files to be created when using the systemd timers features, allowing local
attackers to escalate their privileges to root. This is fixed in v229.

Bugs

Notes

Author Note
tyhicks It looks to me like systemd from the stable phone overlay has the vulnerable code in src/shared/util.c. However, systemd is not used for pid 1 on the phone so marking that specific release as low.

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

13.1%