PT-2015-5219 · Linux Containers+3 · Lxc+3

Roman Fiedler

·

Publicado

2015-09-29

·

Atualizado

2024-06-15

·

CVE-2015-1335

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions lxc versions prior to 1.0.8 lxc versions 1.1.x prior to 1.1.4
Description The issue allows local container administrators to escape AppArmor confinement through a symlink attack. This can be achieved by targeting either a mount target or a bind mount source.
Recommendations For versions prior to 1.0.8, update to version 1.0.8 or later. For versions 1.1.x prior to 1.1.4, update to version 1.1.4 or later.

Exploit

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1962
CVE-2015-1335
DLA-442-1
DSA-3400-1
MGASA-2016-0036
OPENSUSE-SU-2019_1481-1
OPENSUSE-SU-2024:10416-1
SUSE-SU-2015:1829-1
SUSE-SU-2015_1829-1
USN-2753-1
USN-2753-2
USN-2753-3

Produtos afetados

Alt Linux
Suse
Ubuntu
Lxc