CVE-2013-6441
Published: 31 December 2013
The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.
Priority
Status
Package | Release | Status |
---|---|---|
lxc Launchpad, Ubuntu, Debian |
lucid |
Ignored
(reached end-of-life)
|
precise |
Does not exist
(precise was needed)
|
|
quantal |
Ignored
(reached end-of-life)
|
|
raring |
Ignored
(reached end-of-life)
|
|
saucy |
Released
(1.0.0~alpha1-0ubuntu14.1)
|
|
trusty |
Not vulnerable
(1.0.0~beta2-0ubuntu1)
|
|
upstream |
Needs triage
|
|
utopic |
Not vulnerable
(1.0.0~beta2-0ubuntu1)
|
|
vivid |
Not vulnerable
(1.0.0~beta2-0ubuntu1)
|
|
wily |
Not vulnerable
(1.0.0~beta2-0ubuntu1)
|
|
xenial |
Not vulnerable
(1.0.0~beta2-0ubuntu1)
|
|
yakkety |
Not vulnerable
(1.0.0~beta2-0ubuntu1)
|
|
zesty |
Not vulnerable
(1.0.0~beta2-0ubuntu1)
|
|
Patches: upstream: https://github.com/lxc/lxc/commit/f4d5cc8e1f39d132b61e110674528cac727ae0e2 |