The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors.
References
Link | Resource |
---|---|
https://github.com/lxc/lxd/issues/1307 | |
https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/1515689 | |
http://www.ubuntu.com/usn/USN-2809-1 | Patch Vendor Advisory |
Configurations
Information
Published : 2015-11-17 07:59
Updated : 2015-11-18 11:33
NVD link : CVE-2015-8222
Mitre link : CVE-2015-8222
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
canonical
- ubuntu_linux