CVE-2016-15045 - CVE House
Back to Database
Status published High CVE-2016-15045

Deepin lastore-daemon Privilege Escalation via Unsigned .deb Installation

Vulnerability Description

A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepin Technology Co., Ltd.). In versions 0.9.53-1 (Deepin 15.5) and 0.9.66-1 (Deepin 15.7), the D-Bus configuration permits any user in the sudo group to invoke the InstallPackage method without password authentication. By default, the first user created on Deepin is in the sudo group. An attacker with shell access can craft a .deb package containing a malicious post-install script and use dbus-send to install it via lastore-daemon, resulting in arbitrary code execution as root.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-15045

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • King's Way

Affected Vendor

Wuhan Deepin Technology Co., Ltd.

View all reports →

Affected Software

Deepin Linux
Vulnerable Versions:
0.9.53-1 (Deepin 15.5), 0.9.66-1 (Deepin 15.7)

Timeline

Official Publish: July 23rd, 2025
Last Modified: April 7th, 2026
Added to House: July 20th, 2026

CVSS Vectors

Weaknesses (CWE)