9.3
CVSSv2

CVE-2017-18641

Published: 10/02/2020 Updated: 12/02/2020
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linuxcontainers lxc 2.0.0

Vendor Advisories

Debian Bug report logs - #988730 CVE-2017-18641 Package: lxc-templates; Maintainer for lxc-templates is pkg-lxc <pkg-lxc-devel@listsaliothdebianorg>; Source for lxc-templates is src:lxc-templates (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 18 May 2021 18:48:02 UTC Severity: i ...