Vulnerability Name:

CVE-2013-6441 (CCN-95216)

Assigned:2013-12-14
Published:2013-12-14
Updated:2014-02-18
Summary:The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-264
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2013-6441

Source: UBUNTU
Type: UNKNOWN
USN-2104-1

Source: CCN
Type: Ubuntu Bug #1261045
Security bugfix in lxc-sshd template: add ro to the init-script

Source: CONFIRM
Type: UNKNOWN
https://bugs.launchpad.net/ubuntu/%2Bsource/lxc/%2Bbug/1261045

Source: XF
Type: UNKNOWN
lxc-cve20136441-priv-escalation(95216)

Source: CONFIRM
Type: UNKNOWN
https://github.com/dotcloud/lxc/pull/1

Source: CCN
Type: LXC GitHub Repository
LXC - Linux Containers ยท GitHub

Source: CONFIRM
Type: Exploit, Patch
https://github.com/lxc/lxc/commit/f4d5cc8e1f39d132b61e110674528cac727ae0e2

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2013-6441

Vulnerable Configuration:Configuration 1:
  • cpe:/a:linuxcontainers:lxc:0.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.6.5:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.7.3:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.7.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.7.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.7.5:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:0.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:*:*:*:*:*:*:*:* (Version <= 0.9.0)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20136441
    V
    CVE-2013-6441
    2022-05-20
    oval:org.opensuse.security:def:34015
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:31716
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:55976
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:56095
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:31705
    P
    Security update for postgresql, postgresql13, postgresql14 (Important)
    2021-11-20
    oval:org.opensuse.security:def:31704
    P
    Security update for samba (Important)
    2021-11-19
    oval:org.opensuse.security:def:34585
    P
    Security update for systemd (Moderate)
    2021-11-04
    oval:org.opensuse.security:def:34560
    P
    Security update for apache2-mod_auth_openidc (Moderate)
    2021-10-12
    oval:org.opensuse.security:def:30135
    P
    Security update for apache2 (Important)
    2021-10-06
    oval:org.opensuse.security:def:26138
    P
    Security update for python-urllib3 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:55251
    P
    Security update for python-urllib3 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:35267
    P
    Security update for gtk-vnc (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:26129
    P
    Security update for gtk-vnc (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:34521
    P
    Security update for spectre-meltdown-checker (Moderate)
    2021-08-27
    oval:org.opensuse.security:def:31255
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-08-25
    oval:org.opensuse.security:def:32158
    P
    Security update for dbus-1 (Important)
    2021-08-02
    oval:org.opensuse.security:def:31218
    P
    Security update for libsolv (Important)
    2021-06-28
    oval:org.opensuse.security:def:30221
    P
    Security update for arpwatch (Important)
    2021-06-28
    oval:org.opensuse.security:def:34472
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:26074
    P
    Security update for freeradius-server (Moderate)
    2021-06-11
    oval:org.opensuse.security:def:26072
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:36238
    P
    lxc-0.8.0-0.23.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36513
    P
    lxc-0.8.0-0.23.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42645
    P
    lxc-0.8.0-0.23.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26063
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:26062
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:55902
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:57445
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:30078
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:56014
    P
    Security update for cups (Important)
    2021-04-30
    oval:org.opensuse.security:def:34414
    P
    Security update for java-11-openjdk (Important)
    2021-04-26
    oval:org.opensuse.security:def:32071
    P
    Security update for qemu (Important)
    2021-04-16
    oval:org.opensuse.security:def:26213
    P
    Security update for evolution-data-server (Moderate)
    2021-03-19
    oval:org.opensuse.security:def:33785
    P
    Security update for glib2 (Important)
    2021-03-16
    oval:org.opensuse.security:def:34629
    P
    Security update for bind (Important)
    2021-02-18
    oval:org.opensuse.security:def:33784
    P
    Security update for MozillaFirefox (Important)
    2021-01-12
    oval:org.opensuse.security:def:33879
    P
    Security update for openssl-1_0_0 (Important)
    2020-12-09
    oval:org.opensuse.security:def:32014
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32370
    P
    Recommended update for tboot (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32524
    P
    gpg2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25787
    P
    Security update for libwmf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25991
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:26364
    P
    Security update for irssi (Low)
    2020-12-01
    oval:org.opensuse.security:def:26519
    P
    PackageKit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26488
    P
    Security update for cacti, cacti-spine (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26780
    P
    lvm2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27511
    P
    lxc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26394
    P
    Security update for chromium (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26724
    P
    kdebase3-runtime on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27061
    P
    xorg-x11-libxcb-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27796
    P
    Security update for libksba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27333
    P
    xorg-x11-libXrender-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27618
    P
    Security update for ghostscript
    2020-12-01
    oval:org.opensuse.security:def:27963
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28109
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:29774
    P
    Security update for glibc
    2020-12-01
    oval:org.opensuse.security:def:29991
    P
    Security update for libtasn1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30374
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30536
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:54734
    P
    busybox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55417
    P
    xinetd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32419
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33162
    P
    libmusicbrainz4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34111
    P
    Security update for mutt (Important)
    2020-12-01
    oval:org.opensuse.security:def:25788
    P
    Security update for zeromq (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26417
    P
    Security update for Mozilla Thunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26563
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26266
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26639
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26794
    P
    openvpn on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26458
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26808
    P
    postgresql on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27100
    P
    cpio on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27831
    P
    Security update for lxc
    2020-12-01
    oval:org.opensuse.security:def:27344
    P
    libcurl4-openssl1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27675
    P
    Security update for telepathy-gabble
    2020-12-01
    oval:org.opensuse.security:def:28012
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:28747
    P
    Security update for libksba
    2020-12-01
    oval:org.opensuse.security:def:29775
    P
    Security update for gnome-session (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30429
    P
    Security update for xorg-x11-libxcb
    2020-12-01
    oval:org.opensuse.security:def:30580
    P
    Security update for libfreebl3
    2020-12-01
    oval:org.opensuse.security:def:54571
    P
    libmms0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54972
    P
    p7zip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55702
    P
    Security update for xerces-c (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31790
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32458
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33201
    P
    lxc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33796
    P
    Security update for gcc43 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34168
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25799
    P
    Security update for gcc48 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26466
    P
    Security update for irssi (Important)
    2020-12-01
    oval:org.opensuse.security:def:27201
    P
    libnetpbm10 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26347
    P
    Security update for jq (Low)
    2020-12-01
    oval:org.opensuse.security:def:26692
    P
    evince on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26838
    P
    w3m on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26382
    P
    Security update for ffmpeg (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26586
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26959
    P
    libnewt0_52 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27114
    P
    ed on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27408
    P
    ghostscript-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27759
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28051
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28782
    P
    Security update for lxc
    2020-12-01
    oval:org.opensuse.security:def:29786
    P
    Security update for gpgme
    2020-12-01
    oval:org.opensuse.security:def:30478
    P
    Security update for bind (Critical)
    2020-12-01
    oval:org.opensuse.security:def:54572
    P
    libmodplug1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55145
    P
    hplip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55810
    P
    Security update for gdk-pixbuf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31922
    P
    Security update for ghostscript-library (Important)
    2020-12-01
    oval:org.opensuse.security:def:32314
    P
    Security update for rpcbind (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32480
    P
    MozillaFirefox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34257
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:35307
    P
    Security update for lxc
    2020-12-01
    oval:org.opensuse.security:def:25863
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26505
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27236
    P
    lxc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26404
    P
    Security update for irssi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26741
    P
    libcap-progs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27476
    P
    libreadline5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26383
    P
    Security update for Mozilla Thunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26667
    P
    apache2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27012
    P
    perl-HTML-Parser on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27158
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27332
    P
    xorg-x11-libXp-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27536
    P
    php53-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27910
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:28065
    P
    Security update for expat (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29859
    P
    Security update for Linux kernel
    2020-12-01
    oval:org.opensuse.security:def:30517
    P
    Security update for glibc
    2020-12-01
    oval:org.opensuse.security:def:54594
    P
    libpython3_4m1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57371
    P
    Security update for gdk2 (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:25272
    P
    SUSE-SU-2014:0643-1 -- Security update for lxc
    2014-09-08
    oval:org.mitre.oval:def:22432
    P
    USN-2104-1 -- lxc vulnerability
    2014-07-07
    oval:org.opensuse.security:def:80079
    P
    Security update for lxc
    2014-04-01
    oval:com.ubuntu.precise:def:20136441000
    V
    CVE-2013-6441 on Ubuntu 12.04 LTS (precise) - medium.
    2014-02-14
    oval:com.ubuntu.trusty:def:20136441000
    V
    CVE-2013-6441 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-02-14
    oval:com.ubuntu.xenial:def:20136441000
    V
    CVE-2013-6441 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-02-14
    oval:com.ubuntu.xenial:def:201364410000000
    V
    CVE-2013-6441 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-02-14
    BACK
    linuxcontainers lxc 0.1.0
    linuxcontainers lxc 0.2.0
    linuxcontainers lxc 0.2.1
    linuxcontainers lxc 0.3.0
    linuxcontainers lxc 0.4.0
    linuxcontainers lxc 0.5.0
    linuxcontainers lxc 0.5.1
    linuxcontainers lxc 0.5.2
    linuxcontainers lxc 0.6.0
    linuxcontainers lxc 0.6.1
    linuxcontainers lxc 0.6.2
    linuxcontainers lxc 0.6.3
    linuxcontainers lxc 0.6.4
    linuxcontainers lxc 0.6.5
    linuxcontainers lxc 0.7.0
    linuxcontainers lxc 0.7.1
    linuxcontainers lxc 0.7.2
    linuxcontainers lxc 0.7.3
    linuxcontainers lxc 0.7.4
    linuxcontainers lxc 0.7.4.1
    linuxcontainers lxc 0.7.4.2
    linuxcontainers lxc 0.7.5
    linuxcontainers lxc 0.8.0
    linuxcontainers lxc *