3.6
CVSSv2

CVE-2015-6927

Published: 28/09/2015 Updated: 01/07/2017
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

vzctl prior to 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory, which allows local simfs container (CT) root users to change the root password for arbitrary ploop containers, as demonstrated by a symlink attack on the ploop container root.hdd file and then access a control panel.

Vulnerable Product Search on Vulmon Subscribe to Product

openvz vzctl

Vendor Advisories

It was discovered that vzctl, a set of control tools for the OpenVZ server virtualisation solution, determined the storage layout of containers based on the presence of an XML file inside the container An attacker with local root privileges in a simfs-based container could gain control over ploop-based containers Further information on the prereq ...