The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lxc | Mar 31, 2017 | Feb 14, 2014 |
| Suse | — | Upgrade lxcUpgrade lxc-develUpgrade sle-sdk-release | May 29, 2014 | Feb 14, 2014 |
| Ubuntu | — | Upgrade lxc-templates | Nov 8, 2024 | Feb 14, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub