CVE-2015-1331: Medium severity linuxcontainers Lxc vulnerability
Published Aug 12, 2015
·Updated
lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/.
Affected Software
1 affected component
linuxcontainers Lxc<=1.1.2
Event History
Aug 12, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1331?
CVE-2015-1331 has a medium severity level due to its potential for local privilege escalation via a symlink attack.
2
How do I fix CVE-2015-1331?
To fix CVE-2015-1331, upgrade to LXC version 1.1.3 or later to eliminate the vulnerability.
3
What does CVE-2015-1331 exploit?
CVE-2015-1331 exploits a vulnerability in LXC where local users can create arbitrary files through a symlink attack.
4
Which versions of LXC are affected by CVE-2015-1331?
LXC versions up to and including 1.1.2 are affected by CVE-2015-1331.
5
Who is impacted by CVE-2015-1331?
Local users on systems running the vulnerable versions of LXC can be impacted by CVE-2015-1331.