The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing files via unspecified vectors related to a directory path.
References
Configurations
History
No history.
Information
Published : 2016-06-07 14:06
Updated : 2024-02-04 18:53
NVD link : CVE-2015-5228
Mitre link : CVE-2015-5228
CVE.ORG link : CVE-2015-5228
JSON object : View
Products Affected
criu
- checkpoint\/restore_in_userspace
opensuse
- opensuse
CWE
CWE-264
Permissions, Privileges, and Access Controls