Vulnerability Name: | CVE-2015-1331 (CCN-105096) | ||||||||||||||||||||||||||||
Assigned: | 2015-07-22 | ||||||||||||||||||||||||||||
Published: | 2015-07-22 | ||||||||||||||||||||||||||||
Updated: | 2019-05-31 | ||||||||||||||||||||||||||||
Summary: | lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) 3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:C/A:N)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-59 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-1331 Source: SUSE Type: UNKNOWN openSUSE-SU-2019:1481 Source: SUSE Type: UNKNOWN openSUSE-SU-2015:1315 Source: CCN Type: oss-security Mailing List, Wed, 22 Jul 2015 09:24:41 -0500 Security issues in LXC (CVE-2015-1331 and CVE-2015-1334) Source: DEBIAN Type: UNKNOWN DSA-3317 Source: BID Type: UNKNOWN 75999 Source: CCN Type: BID-75999 LXC CVE-2015-1331 Local Directory Traversal Vulnerability Source: UBUNTU Type: UNKNOWN USN-2675-1 Source: CONFIRM Type: Exploit https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1470842 Source: XF Type: UNKNOWN lxc-cve20151331-symlink(105096) Source: CONFIRM Type: UNKNOWN https://github.com/lxc/lxc/commit/72cf81f6a3404e35028567db2c99a90406e9c6e6 Source: CCN Type: LXC Web site Linux Containers - LXC - Introduction Source: MISC Type: UNKNOWN https://service.ait.ac.at/security/2015/LxcSecurityAnalysis.html Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-1331 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |