ALT-PU-2015-2008-1
Package util-linux updated to version 2.27.1-alt1 for branch sisyphus in task 153318.
Closed vulnerabilities
Published: 2017-08-23
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2015-5224
The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- [oss-security] 20150824 CVE-2015-5224 login-utils: file name collision due to incorrect mkstemp use
- [oss-security] 20150824 CVE-2015-5224 login-utils: file name collision due to incorrect mkstemp use
- 76467
- 76467
- https://bugzilla.redhat.com/show_bug.cgi?id=1256686
- https://bugzilla.redhat.com/show_bug.cgi?id=1256686
- https://github.com/karelzak/util-linux/commit/bde91c85bdc77975155058276f99d2e0f5eab5a9
- https://github.com/karelzak/util-linux/commit/bde91c85bdc77975155058276f99d2e0f5eab5a9
Closed bugs
Remove explicit nfs-utils requirement