René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

98 lines
3.1 KiB
JSON

{
"id": "CVE-2015-6927",
"sourceIdentifier": "cve@mitre.org",
"published": "2015-09-28T20:59:09.017",
"lastModified": "2017-07-01T01:29:20.093",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory, which allows local simfs container (CT) root users to change the root password for arbitrary ploop containers, as demonstrated by a symlink attack on the ploop container root.hdd file and then access a control panel."
},
{
"lang": "es",
"value": "Vulnerabilidad en vzctl en versiones anteriores a 4.9.4, determina la estructura del entorno virtual (VE) bas\u00e1ndose en la presencia de root.hdd/DiskDescriptor.xml en el directorio privado VE, lo que permite a los usuarios root del contenedor (CT) simfs local cambiar la contrase\u00f1a de root para contenedores ploop arbitrarios, seg\u00fan lo demostrado por un ataque de enlaces simb\u00f3licos en el contenedor ploop del archivo root.hdd y accediendo entonces a un panel de control."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:P",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 3.6
},
"baseSeverity": "LOW",
"exploitabilityScore": 3.9,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-59"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openvz:vzctl:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.9.3",
"matchCriteriaId": "F6A0E965-E5F7-4C3E-B2DF-3D1BB04569AF"
}
]
}
]
}
],
"references": [
{
"url": "http://www.debian.org/security/2015/dsa-3357",
"source": "cve@mitre.org"
},
{
"url": "https://openvz.org/Download/vzctl/4.9.4",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "https://security.gentoo.org/glsa/201701-30",
"source": "cve@mitre.org"
},
{
"url": "https://src.openvz.org/projects/OVZL/repos/vzctl/commits/9e98ea630ac0e88b44e3e23c878a5166aeb74e1c",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
}
]
}