PT-2017-11398 · Canonical · Ubuntu-Image
Published
2017-07-11
·
Updated
2019-10-03
·
CVE-2017-10600
CVSS v3.1
5.9
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
ubuntu-image version 1.0 before 2017-07-07
Description
The issue allows a local attacker with the same uid as the image creator to have unintended access to cloud-init and snapd directories when the resulting image is booted. This occurs because ubuntu-image, when invoked as non-root, creates files in the resulting image with the uid of the invoking user.
Recommendations
For ubuntu-image version 1.0 before 2017-07-07, consider running the command as root or ensuring that the invoking user's uid does not match any local user on the resulting image to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ubuntu-Image