USN-2675-1
Dashboard / Vulnerabilities / USN-2675-1
USN-2675-1
Summary: lxc vulnerabilities
Details: Roman Fiedler discovered that LXC had a directory traversal flaw when creating lock files. A local attacker could exploit this flaw to create an arbitrary file as the root user. (CVE-2015-1331) Roman Fiedler discovered that LXC incorrectly trusted the container's proc filesystem to set up AppArmor profile changes and SELinux domain transitions. A local attacker could exploit this flaw to run programs inside the container that are not confined by AppArmor or SELinux. (CVE-2015-1334)
References: https://ubuntu.com/security/notices/USN-2675-1, https://ubuntu.com/security/CVE-2015-1331, https://ubuntu.com/security/CVE-2015-1334
Affected packages
Package
Name: lxc
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
