Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-8649

Опубликовано: 01 мая 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 9
CVSS3: 9.1

Описание

lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.

РелизСтатусПримечание
devel

released

2.0.5-0ubuntu4
esm-infra-legacy/trusty

released

1.0.8-0ubuntu0.4
esm-infra/xenial

released

2.0.5-0ubuntu1~ubuntu16.04.3
precise

ignored

end of life
precise/esm

DNE

precise was needs-triage
trusty

released

1.0.8-0ubuntu0.4
trusty/esm

released

1.0.8-0ubuntu0.4
upstream

needed

vivid/stable-phone-overlay

ignored

end of life
vivid/ubuntu-core

DNE

Показывать по

EPSS

Процентиль: 84%
0.02154
Низкий

9 Critical

CVSS2

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
почти 9 лет назад

lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.

CVSS3: 9.1
debian
почти 9 лет назад

lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker ...

suse-cvrf
около 9 лет назад

Security update for lxc

CVSS3: 9.1
github
больше 3 лет назад

lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.

EPSS

Процентиль: 84%
0.02154
Низкий

9 Critical

CVSS2

9.1 Critical

CVSS3