Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2013-6441

Published: 31 December 2013

The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.

Priority

Medium

Status

Package Release Status
lxc
Launchpad, Ubuntu, Debian
lucid Ignored
(reached end-of-life)
precise Does not exist
(precise was needed)
quantal Ignored
(reached end-of-life)
raring Ignored
(reached end-of-life)
saucy
Released (1.0.0~alpha1-0ubuntu14.1)
trusty Not vulnerable
(1.0.0~beta2-0ubuntu1)
upstream Needs triage

utopic Not vulnerable
(1.0.0~beta2-0ubuntu1)
vivid Not vulnerable
(1.0.0~beta2-0ubuntu1)
wily Not vulnerable
(1.0.0~beta2-0ubuntu1)
xenial Not vulnerable
(1.0.0~beta2-0ubuntu1)
yakkety Not vulnerable
(1.0.0~beta2-0ubuntu1)
zesty Not vulnerable
(1.0.0~beta2-0ubuntu1)
Patches:
upstream: https://github.com/lxc/lxc/commit/f4d5cc8e1f39d132b61e110674528cac727ae0e2