UBUNTU-CVE-2015-3248

Source
https://ubuntu.com/security/CVE-2015-3248
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-3248.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2015-3248
Upstream
  • CVE-2015-3248
Withdrawn
2025-07-18T16:43:12Z
Published
2017-09-26T15:29:00Z
Modified
2025-07-16T07:32:54.379965Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

openhpi/Makefile.am in OpenHPI before 3.6.0 uses world-writable permissions for /var/lib/openhpi directory, which allows local users, when quotas are not properly setup, to fill the filesystem hosting /var/lib and cause a denial of service (disk consumption).

References

Affected packages

Ubuntu:24.04:LTS / openhpi

Package

Name
openhpi
Purl
pkg:deb/ubuntu/openhpi@3.8.0-2.1build5?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.0-2.1build5

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libopenhpi-dev",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "libopenhpi3",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "libopenhpi3-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-clients",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-clients-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-dynamic-simulator",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-dynamic-simulator-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-ilo2-ribcl",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-ilo2-ribcl-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-ipmi",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-ipmi-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-ipmidirect",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-ipmidirect-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-oa-soap",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-oa-soap-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-ov-rest",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-ov-rest-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-simulator",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-simulator-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-slave",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-slave-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-snmp-bc",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-snmp-bc-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-sysfs",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-sysfs-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-test-agent",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-test-agent-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-watchdog",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpi-plugin-watchdog-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpid",
            "binary_version": "3.8.0-2.1build5"
        },
        {
            "binary_name": "openhpid-dbgsym",
            "binary_version": "3.8.0-2.1build5"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-3248.json"