Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-1328

EPSS 89.68% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2015-1328

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Ubuntu overlayfs组件提权漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Ubuntu是英国科能(Canonical)公司和Ubuntu基金会共同开发的一套以桌面应用为主的GNU/Linux操作系统。 Ubuntu 15.04及之前版本中的linux数据包3.19.0至21.21版本的overlayfs组件存在本地提权漏洞,该漏洞源于该文件系统没有正确检查文件权限。本地攻击者可利用该漏洞获取系统的管理员权限,完全控制受影响计算机。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2015-1328

#POC DescriptionSource LinkShenlong Link
1This is my SNP project where my ID is IT19366128https://github.com/SR7-HACKING/LINUX-VULNERABILITY-CVE-2015-1328POC Details
2compiled CVE-2015-1328https://github.com/notlikethis/CVE-2015-1328POC Details
3kernel exploithttps://github.com/0x1ns4n3/CVE-2015-1328-GoldenEyePOC Details
4Nonehttps://github.com/BlackFrog-hub/cve-2015-1328POC Details
5kernel exploithttps://github.com/elit3pwner/CVE-2015-1328-GoldenEyePOC Details
6CVE: 2015-1328 On python testhttps://github.com/YastrebX/CVE-2015-1328POC Details
7Nonehttps://github.com/devtz007/overlayfs_CVE-2015-1328POC Details
8Nonehttps://github.com/1mgR00T/CVE-2015-1328POC Details
9Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics, Web Exploitation (SQLi, XSS), Cryptography, and Kernel Exploitation (OverlayFS/CVE-2015-1328) to achieve full root compromise.https://github.com/thieveshkar/RootQuest-CTF-Box-Multi-Stage-Exploitation-VMPOC Details
10A Proof of Concept (PoC) exploit for CVE-2015-1328https://github.com/0xf1d0/CVE-2015-1328POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2015-1328

Please Login to view more intelligence information

Same Patch Batch · n/a · 2016-11-28 · 15 CVEs total

CVE-2015-8970Linux kernel 代码问题漏洞
CVE-2016-8630Linux kernel 代码问题漏洞
CVE-2016-8632Linux kernel 安全漏洞
CVE-2016-8633Linux kernel 访问控制错误漏洞
CVE-2016-8645Linux kernel 访问控制错误漏洞
CVE-2016-8646Linux kernel 代码问题漏洞
CVE-2016-8650Linux kernel 资源管理错误漏洞
CVE-2016-9083Linux kernel 整数溢出漏洞
CVE-2016-9084Linux kernel 整数溢出漏洞
CVE-2016-9178Linux kernel 本地信息泄露漏洞
CVE-2016-9191Linux kernel 本地拒绝服务漏洞
CVE-2016-9313Linux kernel 拒绝服务漏洞
CVE-2016-9555Linux kernel 安全漏洞
CVE-2016-9644Linux kernel 提权漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2015-1328

No comments yet


Leave a comment