CVE-2016-15045 Details
Description
A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepin Technology Co., Ltd.). In versions 0.9.53-1 (Deepin 15.5) and 0.9.66-1 (Deepin 15.7), the D-Bus configuration permits any user in the sudo group to invoke the InstallPackage method without password authentication. By default, the first user created on Deepin is in the sudo group. An attacker with shell access can craft a .deb package containing a malicious post-install script and use dbus-send to install it via lastore-daemon, resulting in arbitrary code execution as root.
A local privilege escalation vulnerability has been identified in the lastore-daemon package manager daemon used in Deepin Linux. This vulnerability is present in lastore-daemon versions 0.9.53-1 (Deepin 15.5) and 0.9.66-1 (Deepin 15.7). The issue arises because the D-Bus configuration allows any user in the sudo group to invoke the InstallPackage method without password authentication. By default, the first user created on Deepin is in the sudo group. An attacker with shell access can exploit this by crafting a .deb package with a malicious post-install script and using dbus-send to install it via lastore-daemon, leading to arbitrary code execution as root.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 23, 2025CISA-ADP
Assessed Jul 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linuxdeepin lastore-daemon | All versions |
CPE
Remediation
| |
| Deepin | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 23, 2025 | CVE Modified | CISA-ADP |
| Jul 23, 2025 | New CVE Received | [email protected] |
Volerion