← back
CVE-2015-1327low

Content-hub DBUS API doesn't prevent confined apps from passing paths to files without access

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 3.9epss 0.8%
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
nono source reports it
Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to the file to create a transfer. This could allow a malicious application using the DBUS API to export file:///etc/passwd which would then send a copy of that file to another app.
CVSS:3.0/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Affected products
Ubuntu · Content Hub