First published: Thu Oct 01 2015(Updated: )
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
linuxcontainers lxc | <=1.0.7 | |
linuxcontainers lxc | =1.1.0 | |
linuxcontainers lxc | =1.1.1 | |
linuxcontainers lxc | =1.1.2 | |
linuxcontainers lxc | =1.1.3 | |
Ubuntu | =14.04 | |
Ubuntu | =15.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1335 is rated as a medium severity vulnerability due to its potential for privilege escalation.
To resolve CVE-2015-1335, upgrade LXC to version 1.0.8 or higher, or 1.1.4 or higher.
CVE-2015-1335 affects LXC versions before 1.0.8 and all 1.1.x versions prior to 1.1.4.
Yes, CVE-2015-1335 can be exploited by local container administrators to escape AppArmor confinement.
CVE-2015-1335 may allow a local attacker to gain elevated privileges and compromise the security of the host system.