CVE-2013-6441: High severity linuxcontainers Lxc vulnerability
Published Feb 14, 2014
·Updated
The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.
Affected Software
24 affected components
linuxcontainers Lxc<=0.9.0
linuxcontainers Lxc=0.1.0
linuxcontainers Lxc=0.2.0
linuxcontainers Lxc=0.2.1
linuxcontainers Lxc=0.3.0
linuxcontainers Lxc=0.4.0
linuxcontainers Lxc=0.5.0
linuxcontainers Lxc=0.5.1
linuxcontainers Lxc=0.5.2
linuxcontainers Lxc=0.6.0
linuxcontainers Lxc=0.6.1
linuxcontainers Lxc=0.6.2
linuxcontainers Lxc=0.6.3
linuxcontainers Lxc=0.6.4
linuxcontainers Lxc=0.6.5
linuxcontainers Lxc=0.7.0
linuxcontainers Lxc=0.7.1
linuxcontainers Lxc=0.7.2
linuxcontainers Lxc=0.7.3
linuxcontainers Lxc=0.7.4
linuxcontainers Lxc=0.7.4.1
linuxcontainers Lxc=0.7.4.2
linuxcontainers Lxc=0.7.5
linuxcontainers Lxc=0.8.0
Remediation
Event History
Feb 14, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6441?
CVE-2013-6441 has been classified with a high severity due to its potential to allow local users to gain elevated privileges.
2
How do I fix CVE-2013-6441?
To fix CVE-2013-6441, update the LXC package to version 1.0.0.beta2 or later to ensure proper permissions when mounting /sbin/init.
3
What versions of LXC are affected by CVE-2013-6441?
CVE-2013-6441 affects LXC versions up to 0.9.0, including versions 0.1.0 to 0.8.0.
4
Who is impacted by CVE-2013-6441?
Local users on systems running vulnerable versions of LXC are at risk of exploitation due to CVE-2013-6441.
5
Is CVE-2013-6441 a remote attack vulnerability?
No, CVE-2013-6441 is a local privilege escalation vulnerability and requires local access to the system.