Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Schroot | Debian | * | 1.6.13 (excluding) |
Debian_linux | Debian | 10.0 (including) | 10.0 (including) |
Debian_linux | Debian | 11.0 (including) | 11.0 (including) |
Schroot | Ubuntu | bionic | * |
Schroot | Ubuntu | esm-infra/xenial | * |
Schroot | Ubuntu | focal | * |
Schroot | Ubuntu | jammy | * |
Schroot | Ubuntu | trusty | * |
Schroot | Ubuntu | upstream | * |
Schroot | Ubuntu | xenial | * |