7.2
CVSSv2

CVE-2013-6441

Published: 14/02/2014 Updated: 18/02/2014
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The lxc-sshd template (templates/lxc-sshd.in) in LXC prior to 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linuxcontainers lxc 0.7.4.2

linuxcontainers lxc 0.7.4.1

linuxcontainers lxc 0.7.3

linuxcontainers lxc 0.7.2

linuxcontainers lxc 0.2.1

linuxcontainers lxc 0.2.0

linuxcontainers lxc 0.1.0

linuxcontainers lxc 0.6.2

linuxcontainers lxc 0.6.1

linuxcontainers lxc 0.6.0

linuxcontainers lxc 0.5.2

linuxcontainers lxc 0.8.0

linuxcontainers lxc 0.7.4

linuxcontainers lxc 0.7.1

linuxcontainers lxc 0.6.5

linuxcontainers lxc 0.6.3

linuxcontainers lxc 0.5.1

linuxcontainers lxc 0.4.0

linuxcontainers lxc

linuxcontainers lxc 0.7.5

linuxcontainers lxc 0.7.0

linuxcontainers lxc 0.6.4

linuxcontainers lxc 0.5.0

linuxcontainers lxc 0.3.0

Vendor Advisories

LXC would allow unintended access to the host, bypassing intended confinement ...
The lxc-sshd template (templates/lxc-sshdin) in LXC before 100beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file ...