PT-2017-11398 · Canonical · Ubuntu-Image

Published

2017-07-11

·

Updated

2019-10-03

·

CVE-2017-10600

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ubuntu-image version 1.0 before 2017-07-07
Description The issue allows a local attacker with the same uid as the image creator to have unintended access to cloud-init and snapd directories when the resulting image is booted. This occurs because ubuntu-image, when invoked as non-root, creates files in the resulting image with the uid of the invoking user.
Recommendations For ubuntu-image version 1.0 before 2017-07-07, consider running the command as root or ensuring that the invoking user's uid does not match any local user on the resulting image to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-10600

Affected Products

Ubuntu-Image