PT-2016-5367 · Red Hat+2 · Ansible+2
Evgeni
·
Published
2016-05-05
·
Updated
2026-06-03
·
CVE-2016-3096
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ansible versions prior to 1.9.6-1
Ansible versions 2.x prior to 2.0.2.0
Description
The issue allows local users to write to arbitrary files or gain privileges via a symlink attack on several files and directories, including
/opt/.lxc-attach-script, the archived container in the archive path directory, or the lxc-attach-script.log or lxc-attach-script.err files in the temporary directory. This is due to a flaw in the create script function within the lxc container module.Recommendations
For Ansible versions prior to 1.9.6-1, update to version 1.9.6-1 or later.
For Ansible versions 2.x prior to 2.0.2.0, update to version 2.0.2.0 or later.
As a temporary workaround, consider restricting access to the
create script function in the lxc container module until a patch is applied.Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ansible
Ansible-Core