CVE-2015-1335
published 2015-10-01CVE-2015-1335: lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount…
PriorityP423high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.46%
37.0th percentile
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | lxc | < lxc 1:1.0.8-1 (bookworm) | lxc 1:1.0.8-1 (bookworm) |
| linuxcontainers | lxc | <= 1.0.7 | — |
| linuxcontainers | lxc | — | — |
| linuxcontainers | lxc | — | — |
| linuxcontainers | lxc | — | — |
| linuxcontainers | lxc | — | — |
| linuxcontainers | lxc | >= 0 < 1:1.0.8-1 | 1:1.0.8-1 |
| linuxcontainers | lxc | >= 0 < 1:1.0.8-1 | 1:1.0.8-1 |
| linuxcontainers | lxc | >= 0 < 1:1.0.8-1 | 1:1.0.8-1 |
| linuxcontainers | lxc | >= 0 < 1:1.0.8-1 | 1:1.0.8-1 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6jr3-ph3x-8q66: lxc-start in lxc before 1
ghsa_unreviewed·2022-05-14
CVE-2015-1335 [HIGH] CWE-59 GHSA-6jr3-ph3x-8q66: lxc-start in lxc before 1
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.
OSV
CVE-2015-1335: lxc-start in lxc before 1
osv·2015-10-01·CVSS 7.2
CVE-2015-1335 [HIGH] CVE-2015-1335: lxc-start in lxc before 1
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.
Ubuntu
LXC vulnerability
vendor_ubuntu·2015-09-29
CVE-2015-1335 LXC vulnerability
Title: LXC vulnerability
Summary: LXC could be made to start containers without AppArmor confinement or access
the host filesystem.
Roman Fiedler discovered a directory traversal flaw in lxc-start. A local
attacker with access to an LXC container could exploit this flaw to run
programs inside the container that are not confined by AppArmor or expose
unintended files in the host to the container.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 6.8
CVE-2014-1335 [MEDIUM] webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux
Debian
CVE-2015-1335: lxc - lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container admi...
vendor_debian·2015·CVSS 7.2
CVE-2015-1335 [HIGH] CVE-2015-1335: lxc - lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container admi...
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.
Scope: local
bookworm: resolved (fixed in 1:1.0.8-1)
bullseye: resolved (fixed in 1:1.0.8-1)
forky: resolved (fixed in 1:1.0.8-1)
sid: resolved (fixed in 1:1.0.8-1)
trixie: resolved (fixed in 1:1.0.8-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container
bugzilla·2015-10-01·CVSS 7.2
CVE-2015-1335 [HIGH] CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container
CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container
Directory traversal flaw was found in lxc.
As reported in http://seclists.org/oss-sec/2015/q3/648 :
"If an attacker constructs a malicious symlink in the target path of a container mount point, the symlink could be mishandled the next time the container is started and the mount operation may be performed at an undesired target location.
Additionally, if the source path of the mount is a malicious symlink relative to the container, the symlink could be mishandled to bind mount an undesired file or directory into the container.
Direct modification of the host's mount table is not possible since a slave copy of the mount table is used.
An example of an attack that is made possibl
Bugzilla
CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container [fedora-all]
bugzilla·2015-10-01·CVSS 7.2
CVE-2015-1335 [HIGH] CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container [fedora-all]
CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container [epel-6]
bugzilla·2015-10-01·CVSS 7.2
CVE-2015-1335 [HIGH] CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container [epel-6]
CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tra
Bugzilla
CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container [epel-7]
bugzilla·2015-10-01·CVSS 7.2
CVE-2015-1335 [HIGH] CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container [epel-7]
CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tra
Bugzilla
CVE-2014-1335 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 6.8
CVE-2014-1335 [MEDIUM] CVE-2014-1335 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
CVE-2014-1335 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2014-1335
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Statement:
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Se
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170045.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171358.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171364.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.htmlhttp://lists.opensuse.org/opensuse-updates/2015-10/msg00023.htmlhttp://www.debian.org/security/2015/dsa-3400http://www.openwall.com/lists/oss-security/2015/09/29/4http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76894http://www.ubuntu.com/usn/USN-2753-1https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1476662https://github.com/lxc/lxc/commit/592fd47a6245508b79fe6ac819fe6d3b2c1289behttps://lists.linuxcontainers.org/pipermail/lxc-devel/2015-September/012434.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/170045.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171358.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171364.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.htmlhttp://lists.opensuse.org/opensuse-updates/2015-10/msg00023.htmlhttp://www.debian.org/security/2015/dsa-3400http://www.openwall.com/lists/oss-security/2015/09/29/4http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76894http://www.ubuntu.com/usn/USN-2753-1https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1476662https://github.com/lxc/lxc/commit/592fd47a6245508b79fe6ac819fe6d3b2c1289behttps://lists.linuxcontainers.org/pipermail/lxc-devel/2015-September/012434.html
2015-10-01
Published