The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors.
References
Link | Resource |
---|---|
http://www.ubuntu.com/usn/USN-2809-1 | Patch Vendor Advisory |
https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/1515689 | |
https://github.com/lxc/lxd/issues/1307 |
Configurations
History
No history.
Information
Published : 2015-11-17 15:59
Updated : 2015-11-18 19:33
NVD link : CVE-2015-8222
Mitre link : CVE-2015-8222
CVE.ORG link : CVE-2015-8222
JSON object : View
Products Affected
canonical
- ubuntu_linux
CWE
CWE-264
Permissions, Privileges, and Access Controls