PT-2017-6652 · Openhpi+2 · Openhpi+2

·

CVE-2015-3248

·

Published

2015-11-19

·

Updated

2023-02-12

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenHPI versions prior to 3.6.0
Description The issue allows local users to cause a denial of service due to disk consumption by filling the filesystem hosting /var/lib. This is possible because the /var/lib/openhpi directory has world-writable permissions. A local user could use this flaw to view, modify, and delete OpenHPI-related data, or fill up the storage device hosting the /var/lib directory.
Recommendations For versions prior to 3.6.0, update to version 3.6.0 or later to resolve the issue. As a temporary workaround, consider restricting write access to the /var/lib/openhpi directory to prevent unauthorized modifications and minimize the risk of disk consumption.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2015_2369
CVE-2015-3248
RHSA-2015:2369
RHSA-2015_2369

Affected Products

Centos
Openhpi
Red Hat