Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8mpq-fmr3-6jxv

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

LXD vulnerable to Race Condition

LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice.

Specific Go Packages Affected

github.com/lxc/lxd/shared

Пакеты

Наименование

github.com/lxc/lxd

go
Затронутые версииВерсия исправления

< 0.0.0-20151004155856-19c6961cc101

0.0.0-20151004155856-19c6961cc101

EPSS

Процентиль: 54%
0.00315
Низкий

8.1 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 7
ubuntu
почти 7 лет назад

LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice.

CVSS3: 7
nvd
почти 7 лет назад

LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice.

CVSS3: 7
debian
почти 7 лет назад

LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsa ...

EPSS

Процентиль: 54%
0.00315
Низкий

8.1 High

CVSS3

Дефекты

CWE-362