PT-2015-2763 · Canonical · Lxd

Stéphane Graber

+1

·

Published

2015-11-17

·

Updated

2015-11-18

·

CVE-2015-8222

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ubuntu lxd versions prior to 0.20-0ubuntu4.1
Description The issue is related to insufficient access control to files in the Ubuntu operating system, specifically in the lxd package. It allows a local attacker to gain privileges through unspecified vectors due to world-readable permissions for /var/lib/lxd/unix.socket.
Recommendations For Ubuntu lxd versions prior to 0.20-0ubuntu4.1, update to version 0.20-0ubuntu4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the /var/lib/lxd/unix.socket file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-12128
CVE-2015-8222

Affected Products

Lxd