CVE-2017-18641: High severity linuxcontainers Lxc vulnerability
Published Feb 10, 2020
·Updated
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
Affected Software
1 affected component
linuxcontainers Lxc=2.0.0
Remediation
Patch Available
Event History
Feb 10, 2020
CVE Published
via MITRE·12:30 AM
Data Sourced
via MITRE·12:30 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18641?
The severity of CVE-2017-18641 is critical.
2
Which software is affected by CVE-2017-18641?
LXC 2.0.0 is affected by CVE-2017-18641.
3
What is the CWE for CVE-2017-18641?
The CWE for CVE-2017-18641 is CWE-287.
4
How can I fix CVE-2017-18641?
To fix CVE-2017-18641, update to a version of LXC that includes the necessary security patches.
5
Is there any additional information about CVE-2017-18641?
For more information about CVE-2017-18641, you can visit the reference link: https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1661447.