CVE-2015-1344
published 2015-12-07CVE-2015-1344: The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writing a pid to…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.38%
30.3th percentile
The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writing a pid to the tasks file.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | lxcfs | <= 0.11 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | lxcfs | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_debian7.2LOW
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LXCFS vulnerabilities
vendor_ubuntu·2015-11-17·CVSS 4.6
CVE-2015-1344 [MEDIUM] LXCFS vulnerabilities
Title: LXCFS vulnerabilities
Summary: Several security issues were fixed in LXCFS.
It was discovered that LXCFS incorrectly enforced directory escapes. A
local attacker could use this issue to possibly escalate privileges.
(CVE-2015-1342)
It was discovered that LXCFS incorrectly checked certain permissions. A
local attacker could use this issue t possibly escalate privileges.
(CVE-2015-1344)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2015-1344: lxcfs - The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly che...
vendor_debian·2015·CVSS 7.2
CVE-2015-1344 [HIGH] CVE-2015-1344: lxcfs - The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly che...
The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writing a pid to the tasks file.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-qr4r-rhfw-j9jj: The do_write_pids function in lxcfs
ghsa_unreviewed·2022-05-17
CVE-2015-1344 [HIGH] GHSA-qr4r-rhfw-j9jj: The do_write_pids function in lxcfs
The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writing a pid to the tasks file.
No detection rules found.
No public exploits indexed.
http://www.ubuntu.com/usn/USN-2813-1https://bugs.launchpad.net/ubuntu/+source/lxcfs/+bug/1512854https://github.com/lxc/lxcfs/commit/8ee2a503e102b1a43ec4d83113dc275ab20a869ahttp://www.ubuntu.com/usn/USN-2813-1https://bugs.launchpad.net/ubuntu/+source/lxcfs/+bug/1512854https://github.com/lxc/lxcfs/commit/8ee2a503e102b1a43ec4d83113dc275ab20a869a
2015-12-07
Published