CVE-2015-2285

Severity CVSS v4.0:
Pending analysis
Type:
CWE-19 Data Handling
Publication date:
12/03/2015
Last modified:
12/04/2025

Description

The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu Vivid 15.04, allows local users to execute arbitrary commands and gain privileges via a crafted file in /run/user/*/upstart/sessions/.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ubuntu:upstart:*:*:*:*:*:*:*:* 1.13.2-0ubuntu7 (including)
cpe:2.3:a:ubuntu:vivid:15.04:*:*:*:*:*:*:*