Lyrie
Critical CVE
CVSS 9.83 sources verified·1 min read
By Lyrie Threat Intelligence·5/13/2026

CRITICAL: CVE-2015-8768 (CVSS 9.8) — click project click

CVE: CVE-2015-8768

CVSS: 9.8 (3.0) — CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: CRITICAL

Status: Critical advisory

Affected

  • click project click
  • canonical ubuntu linux

Summary

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.

Verified Sources

References

  • http://bazaar.launchpad.net/~click-hackers/click/devel/revision/587
  • http://ubuntu.com/usn/usn-2771-1
  • http://www.openwall.com/lists/oss-security/2016/01/12/8
  • http://www.securityfocus.com/bid/96386
  • https://bugs.launchpad.net/ubuntu/+source/click/+bug/1506467
  • https://code.launchpad.net/~cjwatson/click/audit-missing-dot-slash/+merge/274554
  • https://insights.ubuntu.com/2015/10/15/update-on-ubuntu-phone-security-issue/
  • https://plus.google.com/+SzymonWaliczek/posts/3jbG2uiAniF
  • http://bazaar.launchpad.net/~click-hackers/click/devel/revision/587
  • http://ubuntu.com/usn/usn-2771-1

_Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation._

Lyrie Verdict

A vulnerability of this severity is exactly what Lyrie's anti-rogue-AI defense is built for: continuous, autonomous monitoring that doesn't wait for human reaction time.

Validated sources

  1. [1]NVD
  2. [2]GitHub Advisory
  3. [3]MITRE