ISOMAN

CVE

CVE-2016-1581

LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.

Severity
MEDIUM
CVSS
5.5
Published
Modified

Linked Releases

References

  1. http://www.ubuntu.com/usn/USN-2988-1
  2. https://linuxcontainers.org/lxd/news/
  3. http://www.ubuntu.com/usn/USN-2988-1
  4. https://linuxcontainers.org/lxd/news/