Back to search
CVE-2016-3096
Published: Jun 3, 2016
Modified: Aug 5, 2024
PUBLISHED
Description
The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archive_path directory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err files in the temporary directory.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.redhat.com/show_bug.cgi?id=1322925
x_refsource_CONFIRM
FEDORA-2016-cd3cf8e7d0
vendor-advisory
x_refsource_FEDORA
FEDORA-2016-ab154c56dd
vendor-advisory
x_refsource_FEDORA
FEDORA-2016-679c4ddd3c
vendor-advisory
x_refsource_FEDORA
FEDORA-2016-65519440f5
vendor-advisory
x_refsource_FEDORA
FEDORA-2016-28ff51a3f5
vendor-advisory
x_refsource_FEDORA
[ansible-announce] 20160415 Ansible 1.9.6-1 has been released
mailing-list
x_refsource_MLIST
GLSA-201607-14
vendor-advisory
x_refsource_GENTOO
[ansible-announce] 20160419 Ansible 2.0.2.0 has been released
mailing-list
x_refsource_MLIST
https://github.com/ansible/ansible-modules-extras/pull/1941
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now