Search CVE reports


Toggle filters

11 – 18 of 18 results


CVE-2020-9283

Medium priority
Vulnerable

golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server...

4 affected packages

golang-go.crypto, lxd, mongo-tools, snapd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
golang-go.crypto Not affected Not affected Not affected Vulnerable Vulnerable
lxd Not affected Not affected Not affected
mongo-tools Not in release Not in release Needs evaluation Needs evaluation Not in release
snapd Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2019-11840

Medium priority
Vulnerable

An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20...

3 affected packages

golang-go.crypto, lxd, snapd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
golang-go.crypto Not affected Not affected Not affected Vulnerable Vulnerable
lxd Not affected Not affected Not affected
snapd Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2015-1340

Low priority
Ignored

LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have...

1 affected package

lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lxd Not affected
Show less packages

CVE-2015-8308

High priority
Ignored

LXDM before 0.5.2 did not start X server with -auth, which allows local users to bypass authentication with X connections.

1 affected package

lxdm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lxdm Not affected Not affected
Show less packages

CVE-2017-5936

Medium priority
Fixed

OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.

1 affected package

nova-lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nova-lxd Fixed
Show less packages

CVE-2016-1582

Medium priority
Fixed

LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecified vectors.

1 affected package

lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lxd Fixed
Show less packages

CVE-2016-1581

Medium priority
Fixed

LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.

1 affected package

lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lxd Fixed
Show less packages

CVE-2015-8222

Medium priority
Fixed

The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors.

1 affected package

lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lxd
Show less packages