Vulnerability Name: | CVE-2016-10124 (CCN-120504) | ||||||||||||||||||||
Assigned: | 2017-01-09 | ||||||||||||||||||||
Published: | 2017-01-09 | ||||||||||||||||||||
Updated: | 2017-11-13 | ||||||||||||||||||||
Summary: | An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container. | ||||||||||||||||||||
CVSS v3 Severity: | 8.6 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N) 7.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N/E:U/RL:O/RC:C)
7.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||
Vulnerability Type: | CWE-284 | ||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-10124 Source: MISC Type: UNKNOWN http://www.openwall.com/lists/oss-security/2014/12/15/5 Source: MISC Type: UNKNOWN http://www.openwall.com/lists/oss-security/2015/09/03/5 Source: BID Type: UNKNOWN 95404 Source: CCN Type: BID-95404 LXC CVE-2016-10124 Security Bypass Vulnerability Source: XF Type: UNKNOWN lxc-cve201610124-sec-bypass(120504) Source: CCN Type: LXC GIT Repository update lxc-attach manpage Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://github.com/lxc/lxc/commit/e986ea3dfa4a2957f71ae9bfaed406dd6e1ffff6 Source: GENTOO Type: UNKNOWN GLSA-201711-09 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |