Lucene search

K
ubuntuUbuntuUSN-2675-1
HistoryJul 22, 2015 - 12:00 a.m.

LXC vulnerabilities

2015-07-2200:00:00
ubuntu.com
34

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:C/A:N

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

28.9%

Releases

  • Ubuntu 15.04
  • Ubuntu 14.10
  • Ubuntu 14.04 ESM

Packages

  • lxc - Linux Containers userspace tools

Details

Roman Fiedler discovered that LXC had a directory traversal flaw when creating
lock files. A local attacker could exploit this flaw to create an arbitrary
file as the root user. (CVE-2015-1331)

Roman Fiedler discovered that LXC incorrectly trusted the container’s proc
filesystem to set up AppArmor profile changes and SELinux domain transitions. A
local attacker could exploit this flaw to run programs inside the container
that are not confined by AppArmor or SELinux. (CVE-2015-1334)

OSVersionArchitecturePackageVersionFilename
Ubuntu15.04noarchliblxc1< 1.1.2-0ubuntu3.1UNKNOWN
Ubuntu15.04noarchliblxc1-dbgsym< 1.1.2-0ubuntu3.1UNKNOWN
Ubuntu15.04noarchlua-lxc< 1.1.2-0ubuntu3.1UNKNOWN
Ubuntu15.04noarchlua-lxc-dbgsym< 1.1.2-0ubuntu3.1UNKNOWN
Ubuntu15.04noarchlxc< 1.1.2-0ubuntu3.1UNKNOWN
Ubuntu15.04noarchlxc-dbg< 1.1.2-0ubuntu3.1UNKNOWN
Ubuntu15.04noarchlxc-dbgsym< 1.1.2-0ubuntu3.1UNKNOWN
Ubuntu15.04noarchlxc-dev< 1.1.2-0ubuntu3.1UNKNOWN
Ubuntu15.04noarchlxc-dev-dbgsym< 1.1.2-0ubuntu3.1UNKNOWN
Ubuntu15.04noarchlxc-templates< 1.1.2-0ubuntu3.1UNKNOWN
Rows per page:
1-10 of 411

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:C/A:N

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

28.9%