CVE-2013-6441

CWE-2648 documents8 sources
Severity
7.2HIGH
EPSS
0.0%
top 89.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 14
Latest updateMay 17

Description

The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

Debianlxc< 1.0.0-1+3
NVDlinuxcontainers/lxc0.9.0+23

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5m9h-29cp-r3fg: The lxc-sshd template (templates/lxc-sshd2022-05-17
CVEList
CVE-2013-6441: The lxc-sshd template (templates/lxc-sshd2014-02-14
OSV
CVE-2013-6441: The lxc-sshd template (templates/lxc-sshd2014-02-14

📋Vendor Advisories

3
Ubuntu
LXC vulnerability2014-02-12
Red Hat
lxc: sshd template allow privilege escalation on host2013-12-16
Debian
CVE-2013-6441: lxc - The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses rea...2013

💬Community

1
Bugzilla
CVE-2013-6441 lxc: sshd template allow privilege escalation on host2013-12-23
CVE-2013-6441 (HIGH CVSS 7.2) | The lxc-sshd template (templates/lx | cvebase.io