[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256610

 
 

909

 
 

199263

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-6441Date: (C)2014-02-14   (M)2023-12-22


The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.2
Exploit Score: 3.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
USN-2104-1
https://bugs.launchpad.net/ubuntu/%2Bsource/lxc/%2Bbug/1261045
https://github.com/dotcloud/lxc/pull/1
https://github.com/lxc/lxc/commit/f4d5cc8e1f39d132b61e110674528cac727ae0e2

CPE    24
cpe:/a:linuxcontainers:lxc:0.7.5
cpe:/a:linuxcontainers:lxc:0.6.5
cpe:/a:linuxcontainers:lxc:0.7.4
cpe:/a:linuxcontainers:lxc:0.6.4
...
CWE    1
CWE-264
OVAL    1
oval:org.secpod.oval:def:701566

© SecPod Technologies