lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2015-10-01 13:59
Updated : 2019-05-31 14:29
NVD link : CVE-2015-1335
Mitre link : CVE-2015-1335
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
linuxcontainers
- lxc
canonical
- ubuntu_linux