USN-2675-1

Advisory lineage Upstream: 4 Downstream: 0
Published: 22 Jul 2015, 15:01
Last modified:22 Apr 2026, 09:13

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

22 Jul 2015, 15:01
Published
Vulnerability first disclosed
22 Apr 2026, 09:13
Last Modified
Vulnerability information updated

Description

lxc vulnerabilities Roman Fiedler discovered that LXC had a directory traversal flaw when creating lock files. A local attacker could exploit this flaw to create an arbitrary file as the root user. (CVE-2015-1331) Roman Fiedler discovered that LXC incorrectly trusted the container's proc filesystem to set up AppArmor profile changes and SELinux domain transitions. A local attacker could exploit this flaw to run programs inside the container that are not confined by AppArmor or SELinux. (CVE-2015-1334)

Affected Systems

  • ubuntulxc

    < 1.0.7-0ubuntu0.2

References (3)