VDB

MAGEIA-2015-304

MAGEIA-2015-304 PUBLISHED

Roman Fiedler discovered that LXC had a directory traversal flaw when creating lock files. A local attacker could exploit this flaw to create an arbitrary file as the root user (CVE-2015-1331). Roman Fiedler discovered that LXC incorrectly trusted the container's proc filesystem to set up AppArmor profile changes and SELinux domain transitions. A local attacker could exploit this flaw to run programs inside the container that are not confined by AppArmor or SELinux (CVE-2015-1334).

Affected Products

VendorProductVersions
Mageialxc0, 1.0.5-3.1.mga5

Timeline

  • Aug 7, 2015 CVE Updated
  • Aug 7, 2015 CVE Published
  • Mar 17, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›