4.9
CVSSv2

CVE-2015-1331

Published: 12/08/2015 Updated: 31/05/2019
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:N/I:C/A:N

Vulnerability Summary

lxclock.c in LXC 1.1.2 and previous versions allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.

Vulnerable Product Search on Vulmon Subscribe to Product

linuxcontainers lxc

Vendor Advisories

Several security issues were fixed in LXC ...
Debian Bug report logs - #800471 lxc: CVE-2015-1335 Package: src:lxc; Maintainer for src:lxc is pkg-lxc <pkg-lxc-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 29 Sep 2015 20:36:01 UTC Severity: serious Tags: fixed-upstream, patch, security, upstream Found in version ...
Debian Bug report logs - #793298 CVE-2015-1331 CVE-2015-1334 Package: lxc; Maintainer for lxc is pkg-lxc <pkg-lxc-devel@listsaliothdebianorg>; Source for lxc is src:lxc (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 22 Jul 2015 15:15:01 UTC Severity: grave Tags: fixed-upstream, ...
Several vulnerabilities have been discovered in LXC, the Linux Containers userspace tools The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-1331 Roman Fiedler discovered a directory traversal flaw in LXC when creating lock files A local attacker could exploit this flaw to create an arbitrary ...