← Back to CVE List

CVE-2015-1340

Published: 2019-04-22T16:29Z
Last Modified: 2024-11-21T02:25Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt