CVE Vulnerabilities

CVE-2015-1334

Published: Aug 12, 2015 | Modified: May 31, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux confinement by mounting a proc filesystem with a crafted (1) AppArmor profile or (2) SELinux label.

Affected Software

Name Vendor Start Version End Version
Lxc Linuxcontainers * 1.1.2 (including)
Lxc Ubuntu devel *
Lxc Ubuntu precise *
Lxc Ubuntu trusty *
Lxc Ubuntu upstream *
Lxc Ubuntu utopic *
Lxc Ubuntu vivid *
Lxc Ubuntu vivid/stable-phone-overlay *
Lxc Ubuntu wily *
Lxc Ubuntu xenial *
Lxc Ubuntu yakkety *
Lxc Ubuntu zesty *

References