ZeroHour

CVE-2016-1582

CVSS 3.0
5.5 medium
EPSS
<1%p28
Published
()
Modified
Description

LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecified vectors.

Vendors
canonical
Products
ubuntu linux, lxd
Weakness
CWE-200
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.