Vulnerability Name:

CVE-2015-1335 (CCN-106884)

Assigned:2015-09-29
Published:2015-09-29
Updated:2019-05-31
Summary:lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.
CVSS v3 Severity:4.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
4.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
3.7 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-59
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2015-1335

Source: FEDORA
Type: UNKNOWN
FEDORA-2015-9f8f4b182a

Source: FEDORA
Type: UNKNOWN
FEDORA-2015-211974138f

Source: FEDORA
Type: UNKNOWN
FEDORA-2015-ebfe46536f

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2019:1481

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2015:1717

Source: CCN
Type: oss-sec Mailing List, Tue, 29 Sep 2015 17:44:23 +0200
Security issue in LXC (CVE-2015-1335)

Source: DEBIAN
Type: UNKNOWN
DSA-3400

Source: MLIST
Type: UNKNOWN
[oss-security] 20150929 Security issue in LXC (CVE-2015-1335)

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html

Source: BID
Type: UNKNOWN
76894

Source: CCN
Type: BID-76894
LXC CVE-2015-1335 Directory Traversal Vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-2753-1

Source: CONFIRM
Type: UNKNOWN
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1476662

Source: XF
Type: UNKNOWN
lxc-cve20151335-dir-trav(106884)

Source: CONFIRM
Type: UNKNOWN
https://github.com/lxc/lxc/commit/592fd47a6245508b79fe6ac819fe6d3b2c1289be

Source: CCN
Type: LXC Web site
LXC

Source: MLIST
Type: Patch, Vendor Advisory
[lxc-devel] 20150929 LXC security issue - affects all supported releases

Vulnerable Configuration:Configuration 1:
  • cpe:/a:linuxcontainers:lxc:*:*:*:*:*:*:*:* (Version <= 1.0.7)
  • OR cpe:/a:linuxcontainers:lxc:1.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:1.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:1.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:linuxcontainers:lxc:1.1.3:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20151335
    V
    CVE-2015-1335
    2022-06-30
    oval:org.opensuse.security:def:112676
    P
    liblxc-devel-2.0.4-2.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:55316
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:34016
    P
    Security update for xorg-x11-server (Important)
    2021-12-20
    oval:org.opensuse.security:def:57542
    P
    Security update for glib-networking (Important)
    2021-12-13
    oval:org.opensuse.security:def:55981
    P
    Security update for the Linux Kernel (Important)
    2021-12-06
    oval:org.opensuse.security:def:55977
    P
    Security update for xen (Moderate)
    2021-11-29
    oval:org.opensuse.security:def:56096
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:31307
    P
    Security update for postgresql, postgresql13, postgresql14 (Important)
    2021-11-20
    oval:org.opensuse.security:def:34586
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:34561
    P
    Security update for the Linux Kernel (Important)
    2021-10-12
    oval:org.opensuse.security:def:30136
    P
    Security update for xen (Moderate)
    2021-10-07
    oval:org.opensuse.security:def:106156
    P
    liblxc-devel-2.0.4-2.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:55252
    P
    Security update for libqt5-qtbase (Important)
    2021-09-30
    oval:org.opensuse.security:def:56073
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:35268
    P
    Security update for the Linux Kernel (Important)
    2021-09-23
    oval:org.opensuse.security:def:34522
    P
    Security update for sssd (Important)
    2021-08-30
    oval:org.opensuse.security:def:35509
    P
    Security update for cacti, cacti-spine (Moderate)
    2021-08-25
    oval:org.opensuse.security:def:31251
    P
    Security update for unrar (Moderate)
    2021-08-25
    oval:org.opensuse.security:def:31256
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-08-25
    oval:org.opensuse.security:def:30222
    P
    Security update for MozillaFirefox (Important)
    2021-07-16
    oval:org.opensuse.security:def:32136
    P
    Security update for arpwatch (Important)
    2021-06-28
    oval:org.opensuse.security:def:34473
    P
    Security update for cryptctl (Important)
    2021-06-23
    oval:org.opensuse.security:def:36147
    P
    gzip-1.3.12-69.23.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36188
    P
    libgcrypt11-1.5.0-0.17.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:55903
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:30079
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:57446
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:56015
    P
    Security update for bind (Important)
    2021-05-04
    oval:org.opensuse.security:def:34415
    P
    Security update for apache-commons-io (Moderate)
    2021-04-26
    oval:org.opensuse.security:def:34666
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:33786
    P
    Security update for wavpack (Important)
    2021-03-24
    oval:org.opensuse.security:def:55873
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:35291
    P
    Security update for evolution-data-server (Moderate)
    2021-03-19
    oval:org.opensuse.security:def:33785
    P
    Security update for glib2 (Important)
    2021-03-16
    oval:org.opensuse.security:def:34655
    P
    Security update for python (Moderate)
    2021-03-16
    oval:org.opensuse.security:def:28953
    P
    Security update for glib2 (Important)
    2021-03-16
    oval:org.opensuse.security:def:31356
    P
    Security update for python (Moderate)
    2021-03-16
    oval:org.opensuse.security:def:34654
    P
    Security update for apache2 (Moderate)
    2021-03-12
    oval:org.opensuse.security:def:54765
    P
    Security update for java-1_8_0-ibm (Important)
    2021-02-26
    oval:org.opensuse.security:def:34630
    P
    Security update for java-1_7_1-ibm (Important)
    2021-02-18
    oval:org.opensuse.security:def:54743
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:54742
    P
    Security update for ImageMagick (Important)
    2021-01-22
    oval:org.opensuse.security:def:31219
    P
    Security update for openssh (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:32098
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:28918
    P
    Security update for java-1_7_1-ibm (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:31096
    P
    Security update for python (Important)
    2020-12-11
    oval:org.opensuse.security:def:33880
    P
    Security update for openssl-1_1 (Important)
    2020-12-10
    oval:org.opensuse.security:def:30645
    P
    Security update for xorg-x11-libXt
    2020-12-01
    oval:org.opensuse.security:def:55143
    P
    gzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26960
    P
    libopensc2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28222
    P
    Security update for libsndfile (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26587
    P
    libgtop on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27930
    P
    Security update for GraphicsMagick (Low)
    2020-12-01
    oval:org.opensuse.security:def:26809
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27579
    P
    xalan-j2-demo on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31009
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:35350
    P
    Security update for mysql (Important)
    2020-12-01
    oval:org.opensuse.security:def:27585
    P
    xorg-x11-libXp-devel-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54595
    P
    libqt4-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34112
    P
    Security update for mutt (Important)
    2020-12-01
    oval:org.opensuse.security:def:27964
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30537
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:27094
    P
    bzip2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30375
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56147
    P
    Security update for libsoup (Important)
    2020-12-01
    oval:org.opensuse.security:def:27334
    P
    xorg-x11-libXt-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29992
    P
    Security update for tomcat6
    2020-12-01
    oval:org.opensuse.security:def:55588
    P
    Security update for net-snmp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27101
    P
    cron on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28748
    P
    Security update for libksba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30644
    P
    Security update for xorg-x11-libXrender
    2020-12-01
    oval:org.opensuse.security:def:54905
    P
    libpango-1_0-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35042
    P
    Security update for jakarta-commons-fileupload
    2020-12-01
    oval:org.opensuse.security:def:28183
    P
    Security update for various KMPs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31460
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26459
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:27676
    P
    Security update for wireshark
    2020-12-01
    oval:org.opensuse.security:def:55811
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27515
    P
    mercurial on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30952
    P
    Security update for gnuplot (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27541
    P
    pwlib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54573
    P
    libmpfr4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27386
    P
    cyrus-imapd-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30518
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:57372
    P
    Security update for hplip
    2020-12-01
    oval:org.opensuse.security:def:27013
    P
    perl-Tk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27333
    P
    xorg-x11-libXrender-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29860
    P
    Security update for the Linux Kernel
    2020-12-01
    oval:org.opensuse.security:def:27062
    P
    xorg-x11-server-dmx on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28110
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:34985
    P
    Recommended update for ghostscript-library (Important)
    2020-12-01
    oval:org.opensuse.security:def:28134
    P
    Security update for jasper (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31416
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:57616
    P
    Security update for lxc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26395
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:27619
    P
    Security update for glibc
    2020-12-01
    oval:org.opensuse.security:def:27832
    P
    Security update for lxc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27504
    P
    libxcrypt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30862
    P
    Security update for ed (Low)
    2020-12-01
    oval:org.opensuse.security:def:34258
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27527
    P
    openslp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54572
    P
    libmodplug1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27235
    P
    lvm2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30479
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:26885
    P
    e2fsprogs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27846
    P
    Security update for openldap2
    2020-12-01
    oval:org.opensuse.security:def:35465
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29787
    P
    Security update for graphviz (Low)
    2020-12-01
    oval:org.opensuse.security:def:55146
    P
    hyper-v on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28066
    P
    Security update for MozillaFirefox, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:34886
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27911
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:31395
    P
    Security update for perl
    2020-12-01
    oval:org.opensuse.security:def:26384
    P
    Security update for chromium (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27537
    P
    popt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27797
    P
    Security update for lzo
    2020-12-01
    oval:org.opensuse.security:def:27503
    P
    libwsman-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30730
    P
    Security update for MozillaFirefox, mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:55422
    P
    xscreensaver on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27488
    P
    libssh2-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28280
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33797
    P
    Security update for gcc48 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26725
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30430
    P
    Security update for xorg-x11-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35308
    P
    Security update for lxc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26821
    P
    squid3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27789
    P
    Security update for libevent
    2020-12-01
    oval:org.opensuse.security:def:55703
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35438
    P
    Security update for openvpn-openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:28258
    P
    Security update for lxc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29776
    P
    Security update for gnuplot (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54973
    P
    pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35132
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28052
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34750
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:27760
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56266
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:26383
    P
    Security update for Mozilla Thunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27409
    P
    gimp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27159
    P
    kdelibs4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30656
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:27439
    P
    libcurl-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28236
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:26668
    P
    apache2-mod_jk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28081
    P
    Security update for gcc48 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26810
    P
    pure-ftpd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27707
    P
    Security update for augeas (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55418
    P
    xlockmore on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35399
    P
    Security update for openssh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28223
    P
    Security update for libsndfile (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29775
    P
    Security update for gnome-session (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54735
    P
    bzip2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34169
    P
    Security update for openssl (Important)
    2020-12-01
    oval:org.opensuse.security:def:28013
    P
    Security update for apache2-mod_fcgid (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30581
    P
    Security update for ntp (Important)
    2020-12-01
    oval:org.opensuse.security:def:27151
    P
    jakarta-commons-httpclient3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56185
    P
    Security update for libvirt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27345
    P
    libldap-openssl1-2_4-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27115
    P
    elfutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28783
    P
    Security update for lxc (Moderate)
    2020-12-01
    oval:org.cisecurity:def:306
    P
    DSA-3400-1 lxc -- security update
    2016-02-08
    oval:org.opensuse.security:def:80250
    P
    Security update for lxc (Moderate)
    2015-10-05
    oval:org.opensuse.security:def:80080
    P
    Security update for lxc (Moderate)
    2015-10-05
    oval:com.ubuntu.precise:def:20151335000
    V
    CVE-2015-1335 on Ubuntu 12.04 LTS (precise) - medium.
    2015-10-01
    oval:com.ubuntu.trusty:def:20151335000
    V
    CVE-2015-1335 on Ubuntu 14.04 LTS (trusty) - medium.
    2015-10-01
    oval:com.ubuntu.xenial:def:201513350000000
    V
    CVE-2015-1335 on Ubuntu 16.04 LTS (xenial) - medium.
    2015-10-01
    oval:com.ubuntu.xenial:def:20151335000
    V
    CVE-2015-1335 on Ubuntu 16.04 LTS (xenial) - medium.
    2015-10-01
    BACK
    linuxcontainers lxc *
    linuxcontainers lxc 1.1.0
    linuxcontainers lxc 1.1.1
    linuxcontainers lxc 1.1.2
    linuxcontainers lxc 1.1.3
    canonical ubuntu linux 14.04
    canonical ubuntu linux 15.04