Back to search
CVE-2015-6927
Published: Sep 28, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory, which allows local simfs container (CT) root users to change the root password for arbitrary ploop containers, as demonstrated by a symlink attack on the ploop container root.hdd file and then access a control panel.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://openvz.org/Download/vzctl/4.9.4
x_refsource_CONFIRM
GLSA-201701-30
vendor-advisory
x_refsource_GENTOO
DSA-3357
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now