CVE-2015-1815 describes a critical command injection vulnerability in the get_rpm_nvr_by_file_path_temporary function within setroubleshoot versions prior to 3.2.22, impacting Fedora and SELinux setroubleshoot products. This flaw allows remote attackers to execute arbitrary commands by injecting shell metacharacters into file names. With a CVSS score of 10.0, it represents a severe threat with complete compromise of confidentiality, integrity, and availability, requiring no authentication or complex attack conditions. While not listed in CISA's KEV catalog and lacking Metasploit or Nuclei modules, an ExploitDB entry (EDB-36564) indicates a local privilege escalation exploit exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.2.21CPE matchmatch criteria | cpe:2.3:a:selinux:setroubleshoot:*:*:*:*:*:*:*:* | ||
22CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.