Lucene search

K
ubuntuUbuntuUSN-2104-1
HistoryFeb 12, 2014 - 12:00 a.m.

LXC vulnerability

2014-02-1200:00:00
ubuntu.com
32

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%

Releases

  • Ubuntu 13.10

Packages

  • lxc - Linux Containers userspace tools

Details

Florian Sagar discovered that the LXC sshd template set incorrect mount
permissions. An attacker could possibly use this flaw to cause privilege
escalation on the host.

OSVersionArchitecturePackageVersionFilename
Ubuntu13.10noarchlxc-templates< 1.0.0~alpha1-0ubuntu14.1UNKNOWN
Ubuntu13.10noarchliblxc0< 1.0.0~alpha1-0ubuntu14.1UNKNOWN
Ubuntu13.10noarchlxc< 1.0.0~alpha1-0ubuntu14.1UNKNOWN
Ubuntu13.10noarchlxc-dbg< 1.0.0~alpha1-0ubuntu14.1UNKNOWN
Ubuntu13.10noarchlxc-dev< 1.0.0~alpha1-0ubuntu14.1UNKNOWN
Ubuntu13.10noarchpython3-lxc< 1.0.0~alpha1-0ubuntu14.1UNKNOWN

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%