VulnerabilityModified
CVE-2015-1591
The kamailio build in kamailio before 4.2.0-2 process allows local users to gain privileges.
HIGH 7.8EPSS 0.39%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The kamailio build in kamailio before 4.2.0-2 process allows local users to gain privileges.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.39% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- kamailio/kamailio
- Source
- cve@mitre.org
References
- http://cve.killedkenny.io/cve/CVE-2015-1591Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/12/7Mailing List, Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775681Mailing List, Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?msg=17%3Bfilename=0001-fix-fifo-and-ctl-defaults-pointing-to-unsecure-tmp-d.patch%3Batt=1%3Bbug=775681
- https://github.com/kamailio/kamailio/issues/48Third Party Advisory
- https://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1591.htmlThird Party Advisory
- http://cve.killedkenny.io/cve/CVE-2015-1591Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/12/7Mailing List, Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775681Mailing List, Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?msg=17%3Bfilename=0001-fix-fifo-and-ctl-defaults-pointing-to-unsecure-tmp-d.patch%3Batt=1%3Bbug=775681
- https://github.com/kamailio/kamailio/issues/48Third Party Advisory
- https://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1591.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.