CVE Vulnerabilities

CVE-2016-6299

Published: Apr 14, 2017 | Modified: Feb 13, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file.

Affected Software

Name Vendor Start Version End Version
Fedora Fedoraproject 23 (including) 23 (including)
Fedora Fedoraproject 24 (including) 24 (including)
Fedora Fedoraproject 25 (including) 25 (including)
Mock Ubuntu artful *
Mock Ubuntu esm-apps/xenial *
Mock Ubuntu trusty *
Mock Ubuntu upstream *
Mock Ubuntu xenial *
Mock Ubuntu yakkety *
Mock Ubuntu zesty *

References