Executive Summary

Informations
Name CVE-2019-15793 First vendor Publication 2020-04-24
Vendor Cve Last vendor Modification 2020-05-01

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Overall CVSS Score 8.8
Base Score 8.8 Environmental Score 8.8
impact SubScore 6 Temporal Score 8.8
Exploitabality Sub Score 2
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Changed Confidentiality Impact High
Integrity Impact High Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score 4.6 Attack Range Local
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were translating them into init_user_ns, whereas they should have been translated into the s_user_ns for the lower filesystem. This resulted in using ids other than the intended ones in the lower fs, which likely did not map into the shifts s_user_ns. A local attacker could use this to possibly bypass discretionary access control permissions.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15793

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-276 Incorrect Default Permissions

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 2
Os 2

Sources (Detail)

Source Url
MISC https://git.launchpad.net/~ubuntu-kernel/ubuntu/+source/linux/+git/eoan/commi...
https://usn.ubuntu.com/usn/usn-4183-1
https://usn.ubuntu.com/usn/usn-4184-1

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
Date Informations
2024-02-02 02:04:21
  • Multiple Updates
2024-02-01 12:17:19
  • Multiple Updates
2023-09-05 12:59:26
  • Multiple Updates
2023-09-05 01:17:00
  • Multiple Updates
2023-09-02 12:58:42
  • Multiple Updates
2023-09-02 01:17:17
  • Multiple Updates
2023-08-12 13:02:37
  • Multiple Updates
2023-08-12 01:16:35
  • Multiple Updates
2023-08-11 12:56:24
  • Multiple Updates
2023-08-11 01:17:04
  • Multiple Updates
2023-08-06 12:54:45
  • Multiple Updates
2023-08-06 01:16:29
  • Multiple Updates
2023-08-04 12:55:01
  • Multiple Updates
2023-08-04 01:16:40
  • Multiple Updates
2023-07-14 12:55:00
  • Multiple Updates
2023-07-14 01:16:36
  • Multiple Updates
2023-06-06 12:48:52
  • Multiple Updates
2021-05-04 13:31:19
  • Multiple Updates
2021-04-22 02:45:48
  • Multiple Updates
2020-05-23 02:25:40
  • First insertion