Vulnerability Name: | CVE-2015-8222 (CCN-108345) | ||||||||
Assigned: | 2015-11-17 | ||||||||
Published: | 2015-11-17 | ||||||||
Updated: | 2015-11-18 | ||||||||
Summary: | The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors. | ||||||||
CVSS v3 Severity: | 8.4 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-8222 Source: UBUNTU Type: Patch, Vendor Advisory USN-2809-1 Source: CCN Type: Launchpad #1515689 Wrong mode on unix.socket when socket activated Source: CONFIRM Type: UNKNOWN https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/1515689 Source: XF Type: UNKNOWN ubuntu-cve20158222-priv-esc(108345) Source: CONFIRM Type: UNKNOWN https://github.com/lxc/lxd/issues/1307 | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |