3.3

CVE-2018-6556

The lxc-user-nic component of LXC allows unprivileged users to open arbitrary files

lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Linuxcontainers ≫ Lxc Version >= 2.0.0 <= 2.0.9
Linuxcontainers ≫ Lxc Version >= 3.0.0 < 3.0.2
Suse ≫ Caas Platform Version 1.0
Suse ≫ Caas Platform Version 2.0
Suse ≫ Openstack Cloud Version 6
Suse ≫ Suse Linux Enterprise Server Version 11 Update sp3 SwEdition ltss
Suse ≫ Suse Linux Enterprise Server Version 11 Update sp4
Opensuse ≫ Leap Version 15.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.263
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.3 1.8 1.4
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.html
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00074.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00076.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00091.html
Third Party Advisory
Mailing List
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1783591
Third Party Advisory
Issue Tracking
https://bugzilla.suse.com/show_bug.cgi?id=988348
Patch
Issue Tracking
https://security.gentoo.org/glsa/201808-02
Third Party Advisory
https://usn.ubuntu.com/usn/usn-3730-1
Third Party Advisory