First published: Mon Feb 10 2020(Updated: )
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxcontainers Lxc | =2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-18641 is critical.
LXC 2.0.0 is affected by CVE-2017-18641.
The CWE for CVE-2017-18641 is CWE-287.
To fix CVE-2017-18641, update to a version of LXC that includes the necessary security patches.
For more information about CVE-2017-18641, you can visit the reference link: https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1661447.